Educause Security Discussion mailing list archives
Re: False positives scanning Red Hat servers running Apache
From: Chris Green <cmgreen () UAB EDU>
Date: Mon, 30 Apr 2007 08:13:04 -0500
Wyman Miles wrote:
If you're willing to supply login credentials to your scanner, it'll invariably be much more accurate. But, now you've introduced a maintenance issue and potentially a security risk.
While griping about Tenable, I seem to recall a day when they did write the scripts that did a lot more than version checking. They still seem now and then. I spend a LOT more time filtering out the remote patch check scripts which just are not useful to me in the distributed organization. Unfortunately, I don't think other vendors are much better in this regard.
Current thread:
- Re: False positives scanning Red Hat servers running Apache, (continued)
- Re: False positives scanning Red Hat servers running Apache Julian Y. Koh (Apr 26)
- Re: False positives scanning Red Hat servers running Apache Wyman Miles (Apr 26)
- Re: False positives scanning Red Hat servers running Apache Aaron Lafferty (Apr 26)
- Re: False positives scanning Red Hat servers running Apache Allison Henry (Apr 26)
- Re: False positives scanning Red Hat servers running Apache Wyman Miles (Apr 26)
- Re: False positives scanning Red Hat servers running Apache Steve Brukbacher (Apr 26)
- Re: False positives scanning Red Hat servers running Apache Russell Fulton (Apr 26)
- Re: False positives scanning Red Hat servers running Apache Clifford Collins (Apr 26)
- Re: False positives scanning Red Hat servers running Apache Bill Ogle (Apr 26)
- Re: False positives scanning Red Hat servers running Apache Mark Rogowski (Apr 26)
- Re: False positives scanning Red Hat servers running Apache Chris Green (Apr 30)
- Re: False positives scanning Red Hat servers running Apache Wyman Miles (Apr 30)
