Security Basics mailing list archives
Re: Opinions on vulnerability scanning practice?
From: Mitch Pope <MPope () gwail com au>
Date: Fri, 4 Aug 2006 09:19:59 +1000
It depends what they mean by "vulnerability scan". If the scan involved port scanning your server then they more than likely are breaking the law by doing so. However if all they did was check for website vulnerabilities, then while it might be a little rude it's perfectly legal assuming they don't actually try and exploit the server! If you're running such a very public and visible server you should know exactly what is happening. That means you have a firewall and you read your logs and should someone run a portscan or any other kind of unauthorised connection your firewall starts droping any packets from that persons IP address destined for any host on your subnet. Then all the risk management firm has to say is "this guy has great security". Kind Regards, Mitch Pope I'd like to get a community opinion on this. We're a union that provides free web hosting to a number of related non-profit organizations. Some of them have gone to a third-party provider for e-commerce functionality, and obviously want to link to that provider from their sites on our server. Wanting to set up merchant accounts for these organizations, that provider's e-commerce service (Beanstream) had a risk management firm run a vulnerability scan on our server, stating that Visa requires AIS end-to-end compliance within the Visa payment system. Now, I recognize the desire to prevent pharming and similar attacks that could occur were my system to be compromised, but my first response was: "Who the ^*$$* do you think you are to run a scan on my system without permission?" What's the deal here? Am I out of line? Is this normal practice? ********************************************************************** This email message is intended for the named recipient(s) only. Please advise GWA if you have received this email message in error and delete all copies. This email message may contain information which represents the views of the sender and not necessarily those of GWA and/or subsidiary companies. Virus protection is in place at GWA however liability for viruses or similar in any attachment remains the responsibility of the recipient. If you are the intended recipient of this email message you should not copy, disclose or distribute this email message without the authority of GWA. GWA cannot guarantee this email message has not been intercepted or interfered with as it traverses the Internet. Internet email messages sent to GWA are not private communications and may be viewed by GWA at any time to ensure compliance with the GWA Electronic Communications Policy available at http://policy.gwail.com.au. Please be familiar with this policy if you intend sending email to GWA or Subsidiary companies. ********************************************************************** --------------------------------------------------------------------------- This list is sponsored by: Norwich University EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life. http://www.msia.norwich.edu/secfocus ---------------------------------------------------------------------------
Current thread:
- Opinions on vulnerability scanning practice? rgutter (Aug 03)
- RE: Opinions on vulnerability scanning practice? David Gillett (Aug 04)
- Re: Opinions on vulnerability scanning practice? Mitch Pope (Aug 04)
- Re: Opinions on vulnerability scanning practice? Ansgar -59cobalt- Wiechers (Aug 05)
- Re: Opinions on vulnerability scanning practice? Eric Furman (Aug 05)
- Re: Opinions on vulnerability scanning practice? Irwan Ismail (Aug 04)
- <Possible follow-ups>
- RE: Opinions on vulnerability scanning practice? Jeffrey Wei (Aug 04)
- Re: Opinions on vulnerability scanning practice? krymson (Aug 04)
- RE: Opinions on vulnerability scanning practice? Krpata, Tyler (Aug 04)
- Re: Opinions on vulnerability scanning practice? knox . justin (Aug 04)
- Re: Opinions on vulnerability scanning practice? benjaminz (Aug 04)
- Re: Opinions on vulnerability scanning practice? gazwj (Aug 04)
- Re: Opinions on vulnerability scanning practice? simonis (Aug 04)
