RE: [fw-wiz] commercial va

From: Ben Nagy (ben@iagu.net)
Date: 04/17/03

  • Next message: Ahmed, Balal: "RE: [fw-wiz] PIX Licensed Connections Limit"
    From: "Ben Nagy" <ben@iagu.net>
    To: "'Behm, Jeffrey L.'" <BehmJL@bvsg.com>
    Date: Thu, 17 Apr 2003 09:43:12 +0200
    

    > -----Original Message-----
    > From: firewall-wizards-admin@honor.icsalabs.com
    > [mailto:firewall-wizards-admin@honor.icsalabs.com] On Behalf
    > Of Behm, Jeffrey L.
    > Sent: Wednesday, 16 April 2003 8:02 PM
    > To: firewall-wizards@honor.icsalabs.com
    >
    > Do you have any specifics on what got "freaked out?" by
    > nessus?

    Network infrastructure, particularly (in my case) switches with spanning
    tree enabled. I still feel the pain. This was a while ago, yada yada, but
    AFAIK it's still a fairly widely held belief. Most people recommend that you
    avoid routing your nessus scans around a lot, or scanning your
    infrastructure (routers, switches, firewalls) devices too heavily.

    Obviously if you don't run in safe mode you have even more potential
    problems, but I already assumed that nobody sane would do that on a
    production network.

    I have also "heard" (this is code for "I can't remember where I heard it,
    nor can I back it up from my own experience") that some hosts or servers
    have had problems with safe nessus scans and crashed anyway.

    As for the rest of the thread, I'll shut up now that there has been a decent
    discussion - I was terrified that the poster would go and evaluate nothing
    but ISS and Cybercop - which is probably not a good plan.

    General points that I would like to underline:

    - VA can't yet replace a smart security person in terms of turning scan
    results into sensible risk management and remediation.

    - The whole VA space is still evolving. Event correlation, distributed
    scanning, automatic remediation and early attempts at intelligent risk or
    threat assessment are already out there from a number of vendors.

    - No tool is perfect, and while everyone is working to reduce false
    positives and false negatives, writing checks that don't crash things is
    actually pretty hard. Don't assume that your tool is giving you the gospel.

    > I.E. what in particular should one be concerned
    > about? [...]
    >
    > Please enlighten me if I am astray.
    >
    >
    > At some point, Ben Nagy spewed:

    Spewed? ;)

    > > You should look at Retina as well. For freeware, Nessus is
    > also cool,
    > > but I, personally, would be very careful running it on production
    > > networks (we often recommend that people use nessus as a
    > complement to
    > > Retina, but it does have a habit of freaking out networks).

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Ahmed, Balal: "RE: [fw-wiz] PIX Licensed Connections Limit"

    Relevant Pages

    • Re: Single domain two IP subnets
      ... hardware or any of the complexities of "network hardward ... I never criticize anyone's typing as long as the words can ... Cisco ISL VLANS are history. ... Newer Cisco switches don't even support ISL ...
      (microsoft.public.win2000.dns)
    • Re: new switching technologies
      ... mixed with stackable switches. ... i havent used these kit versions, but this is maybe the 5th or 6th iteration ... of a fix looking for a problem for L2 network resilience / load balancing. ... optimal one is what routing protocols were designed for and what they are ...
      (comp.dcom.lans.ethernet)
    • Re: priviledge escalation techniques
      ... you've all the tools you need, and you can install additional ones (to ... If I press that BEFORE login, a CLI as SYSTEM is started, I can launch ... If the network is switched, perhaps you need an ARP poisoning tool. ... switches) in such a way that you can fool an ARP poisoning attempt. ...
      (Pen-Test)
    • Re: LISP for web
      ... Any large scale web app that is business critical is based on a few ... -> So you need at least two routers, two switches, two machines ... ... Load balancing is done based on content and on network traffic ...
      (comp.lang.lisp)
    • Re: Proper way to install shielded ethernet
      ... His switches had not been reporting errors, yet once everything was swapped out, his apps were suddenly rock-solid. ... Since his switches hadn't cried foul, he's assumed his network was clean and didn't give it another thought, so he was very suprised to find the issues resolved. ... That led to problems that I believe were caused by expansion and contraction of various components touching on the fiber, which led me to call in an industrial cabling guy. ... Which led to an argument over the grounding scheme.... ...
      (comp.dcom.lans.ethernet)