RE: Should webservers, eg. IIS 6 have anti--virus installed on them?

S_Dorn/CIB_at_BANKCIB.COM
Date: 07/20/05

  • Next message: Matthew Farrenkopf: "RE: Should webservers, eg. IIS 6 have anti--virus installed on them?"
    To: Harlan Carvey <keydet89@yahoo.com>
    Date: Wed, 20 Jul 2005 12:16:31 -0500
    
    

    CIL....

    Stefan Dorn

    Harlan Carvey <keydet89@yahoo.com> wrote on 07-19-2005 06:49:09 PM:

    >
    > > I have a completely different view. I think that
    > > AV, while not the silver
    > > bullet, is a solid line of defence.
    >
    > Perhaps, but from what? It won't protect the box from
    > being broken into, and the argument that it will
    > protect you from things we don't know about yet just
    > doesn't hold.

    If someone were to compromise the server enough so that they could upload
    a rootkit or something, AV could potentially detect some or all of it, if
    they used a kit they didn't create themselves. The real question should be
    "what harm is caused by having AV installed on a web server?".

    >
    > > The more
    > > lines of defence you have, the more proactively you
    > > have secured your environment.
    >
    > And the more things you have to manage, and the more
    > things you have to look at when troubleshooting an
    > issue...and yet another set of logs that you have to
    > review.
    >

    Policies and procedures can help mitigate this, along with proper
    configuration and automation of updates and reporting. If some viral
    outbreak occurred exploiting a component of that server's OS or web
    services, I'd rather have more logging than less logging available to
    determine what happened.

    > > In a perfect world everything would be nicely
    > > secured, things like Windows
    > > and TCP/IP would have been designed for security and
    > > we would all be proactive not reactive.
    >
    > But you can be proactive with Windows...there are a
    > great number of things you can do to secure a Windows
    > system proactively. The problem is that few of them
    > are done.
    >

    There are a great many, and indeed few of them are properly executed, in
    general. But in the case where a system administrator accidentally does
    not follow a strict and secure protocol or procedure, even just one time
    (lets say they don't verify a checksum on an update file, and it is
    infected somehow,) I would rather give that server an additional line of
    defense.

    All other things aside, trying to explain why there's no AV installed on
    the web server to your board of directors or president (after a 3rd party
    audit makes a stink about it) will probably cost your IT staff more time
    and money than just installing the AV in the first place.

    > Harlan
    >
    >
    > ------------------------------------------
    > Harlan Carvey, CISSP
    > "Windows Forensics and Incident Recovery"
    > http://www.windows-ir.com
    > http://windowsir.blogspot.com
    > ------------------------------------------
    >
    >
    ---------------------------------------------------------------------------
    >
    >
    ---------------------------------------------------------------------------
    >

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Matthew Farrenkopf: "RE: Should webservers, eg. IIS 6 have anti--virus installed on them?"

    Relevant Pages

    • Re: Dell PowerEdge 2450 & Win2k3 server
      ... The other thing you can do is try to run just one CPU and see if one of the ... Enterprise server sp1. ... I get this error after the windows setup process. ... Tried installing with the PERC and also tried installing using the ...
      (microsoft.public.windows.server.general)
    • Re: Windows Advanced Server 2000 PKI
      ... following as a rough guideline for installing a Windows 2000 Enterprise or ... - install or reconfigure your DHCP server accordingly ... Join Windows 2000 member server to new domain and install Enterprise or ... > We would like to setup PKI having server2 as the> certificate authority. ...
      (microsoft.public.win2000.security)
    • Re: Time learning openSUSE
      ... should think about when talking to Windows admins ... I must honestly say I have had more downtime on the Linux server then on ... installing Linux on Bill Gates PC. ...
      (alt.os.linux.suse)
    • Re: DB2 queries without using MF.
      ... That Windows data cannot be adequately secured is a canard. ... well now we know how secure the the links are just wonder how the 37 *MILLION* credit card numbers that got stolen... ... Don't confuse the desktop PC with the server. ... I have experienced an auditor trying to do his job and he is twarted at every turn. ...
      (bit.listserv.ibm-main)
    • Re: hardware firewall
      ... >> comment was about firewalls and security based on his question. ... he wanted to limit the connections to his Windows development web server ... month and am installing over $328K worth of them next week. ... >> I would assume, from your comment, that you've never run a Windows based ...
      (comp.security.misc)