Security Basics mailing list archives

Re: Opinions on vulnerability scanning practice?


From: Mitch Pope <MPope () gwail com au>
Date: Fri, 4 Aug 2006 09:19:59 +1000

It depends what they mean by "vulnerability scan".  If the scan involved 
port scanning your server then they more than likely are breaking the law 
by doing so.  However if all they did was check for website 
vulnerabilities, then while it might be a little rude it's perfectly legal 
assuming they don't actually try and exploit the server!

If you're running such a very public and visible server you should know 
exactly what is happening.  That means you have a firewall and you read 
your logs and should someone run a portscan or any other kind of 
unauthorised connection your firewall starts droping any packets from that 
persons IP address destined for any host on your subnet.  Then all the 
risk management firm has to say is "this guy has great security".

Kind Regards,
Mitch Pope

I'd like to get a community opinion on this. We're a union that provides 
free web hosting to a number of related non-profit organizations. Some of 
them have gone to a third-party provider for e-commerce functionality, and 
obviously want to link to that provider from their sites on our server.

Wanting to set up merchant accounts for these organizations, that 
provider's e-commerce service (Beanstream) had a risk management firm run 
a vulnerability scan on our server, stating that Visa requires AIS 
end-to-end compliance within the Visa payment system.

Now, I recognize the desire to prevent pharming and similar attacks that 
could occur were my system to be compromised, but my first response was: 
"Who the ^*$$* do you think you are to run a scan on my system without 
permission?"

What's the deal here? Am I out of line? Is this normal practice? 


**********************************************************************
This email message is intended for the named recipient(s) only. Please
advise GWA if you have received this email message in error and delete
all  copies.    This  email  message  may  contain  information  which
represents the views  of  the sender and  not necessarily those of GWA
and/or  subsidiary companies.  Virus  protection  is  in  place at GWA
however liability for viruses or similar in any attachment remains the
responsibility of the recipient.  If you are the intended recipient of
this email message you should not copy, disclose  or  distribute  this
email message without the authority of GWA.  GWA cannot guarantee this
email message  has  not  been intercepted  or  interfered with  as  it
traverses the Internet.  Internet email messages sent to  GWA  are not
private communications  and may be viewed by GWA at any time to ensure
compliance with the  GWA Electronic Communications Policy available at
http://policy.gwail.com.au. Please be familiar with this policy if you
intend sending email to GWA or Subsidiary companies.
********************************************************************** 

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence 
in Information Security. Our program offers unparalleled Infosec management 
education and the case study affords you unmatched consulting experience. 
Using interactive e-Learning technology, you can earn this esteemed degree, 
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: