RE: Should webservers, eg. IIS 6 have anti--virus installed on them?

From: Harlan Carvey (keydet89_at_yahoo.com)
Date: 07/20/05

  • Next message: Wozny, Scott (US - New York): "RE: Should webservers, eg. IIS 6 have anti--virus installed on them?"
    Date: Wed, 20 Jul 2005 10:37:54 -0700 (PDT)
    To: focus-ms@securityfocus.com
    
    

    Brady,
     
    > As for the rest, It's obvious we disagree because
    > the logic that we
    > don't know what the next threat may be holds with
    > me, or that we could
    > have missed something when securing the server
    > (again that infallibility thing) holds with me.

    IMHO, it's not a matter of infallibility at all. What
    I am saying is that new threats won't necessarily be
    covered by A/V software. Also, if something was
    missed in the configuration of the web server, then
    there's a problem with the security process that needs
    to be fixed, and when the problem lies in the process,
    installing an additional software package is a poor
    band-aid, at best.

    > And correct that an A/V product without a definition
    > for a virus is
    > useless, unless you use one like I do that has
    > heuristic scanning adding some level of protection.

    That's fine. How many alerts to you get on a
    daily/weekly/monthly basis from your A/V package,
    specifically the one installed on your web server?

    > Also, many AV vendors now have definition
    > for well-known "hacker tools" (I hate term, but
    > can't think of a better
    > one). Many worms and script-kiddies use the
    > vulnerability to drop in
    > files that do the real damage. Drop in an FTP
    > server (reason for
    > firewall), backdoor (reason for firewall),
    > keylogger, whatever, and execute as SYSTEM.

    If an attacker or worm is able to gain SYSTEM access
    to your system, no amount of A/V is going to help.
    Many worms are actively seeking out A/V processes and
    attempting to disable them.

    > If there was no patch for the vulnerability,
    > wouldn't it be nice to an AV product to grab those?

    Again, if the attacker (person, kiddie, worm,
    whatever) is executing as SYSTEM...what's the point?

    > And lastly if you state that AV or whatever is not
    > needed if you
    > properly secure your systems, that is an attitude of
    > infallibility, and
    > therefore I caution. You can not guarantee
    > security! You may not need
    > AV, but not for that reason.

    Okay, I'll bite...for what reason?

    Harlan

    ------------------------------------------
    Harlan Carvey, CISSP
    "Windows Forensics and Incident Recovery"
    http://www.windows-ir.com
    http://windowsir.blogspot.com
    ------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Wozny, Scott (US - New York): "RE: Should webservers, eg. IIS 6 have anti--virus installed on them?"

    Relevant Pages

    • Re: Need help setting up remote desktop.
      ... if your Web server is registered with the WINS server as ... Is there any particular reason you want to use the web based method? ... those folders, the way I can with the people who are on the home network ... however, as of this writing, I have not finished reading the instructions ...
      (microsoft.public.windowsxp.network_web)
    • Re: Should webservers, eg. IIS 6 have anti--virus installed on them?
      ... a/v deployment set in such a way] that I can do this. ... Even Microsoft has expanded their patch testing process to include ... Add that to your risk factors and decide accordingly. ... >>If a web server is just a web server, ...
      (Focus-Microsoft)
    • Re: server security
      ... This is a basic web server that runs email, web and a couple other things. ... He that will not reason is a bigot; he that cannot reason is a fool; he that ... Securing Apache Web Server with thawte Digital Certificate ...
      (Security-Basics)
    • RE: Should webservers, eg. IIS 6 have anti--virus installed on them?
      ... as the web server. ... > rule out any security measure based on cost. ... Let's say Joe SysAdmin does install the A/V ... A/V software is ...
      (Focus-Microsoft)
    • Re: Python on the Web
      ... which is probably the reason I haven't found ... that the web server creates a single FCGI process. ... FCGI process is actually the entry point of the Framework/Application ... but one reason is that I want to use Python 3.1 and as I ...
      (comp.lang.python)