Bugtraq mailing list archives
Re: ISS Internet Scanner Cannot be relied upon for conclusive
From: briank () conxion net (Brian Koref)
Date: Thu, 11 Feb 1999 19:07:52 -0800
Network and System security IS NOT a point solution. ISS scanner is just one tool. I know I'll never fully secure any one system, let alone entire disparate enterprises comprised of multitues of various modern and legacy OS/hardware/software, rogue programs, etc...To keep up with with patches, security bugs, poorly written C, CGI and perl scripts, rogue java applets is frustrating and a full time job... I know this isn't quite the forum for the above comment, but I do want to mention a thought regarding banners. I know of some sysadmins, who change the banners for sendmail, ftp, telnet, imap, etc...to "disguise" services. I'm a little concerned about false negatives, if scanner uses the "assumption" model for some of it's scanning methodology. If the tool behaves in that fashion, then it should be noted in the report...BK
Current thread:
- Re: ISS Internet Scanner Cannot be relied upon for conclusive, (continued)
- Re: ISS Internet Scanner Cannot be relied upon for conclusive Joel Eriksson (Feb 12)
- More Comments: Security Scanners. Craig H. Rowland (Feb 12)
- Re: ISS Internet Scanner Cannot be relied upon for conclusive Adam Shostack (Feb 10)
- remote fakebo shell exploit Groovy Pants Gus (Feb 11)
- AW: Security Bug in Bintec Router Firmware (CLID) Thomas Schmidt (Feb 11)
- Re: Security Bug in Bintec Router Firmware (CLID) Pascal Gienger (Feb 11)
- Seeking Policy Data Loftin C. Woodiel (Feb 11)
- Re: ISS Internet Scanner Cannot be relied upon for conclusive David LeBlanc (Feb 09)
- Re: ISS Internet Scanner Cannot be relied upon for conclusive der Mouse (Feb 10)
- Re: ISS Internet Scanner Cannot be relied upon for conclusive Ulf Munkedal (Feb 10)
- Re: ISS Internet Scanner Cannot be relied upon for conclusive Brian Koref (Feb 11)
- Buffer overflow in Serve-U Ryan Sweat (Feb 11)
- Re: ISS Internet Scanner Cannot be relied upon for conclusive Phil Waterbury (Feb 11)
- Re: ISS Internet Scanner Cannot be relied upon for conclusive Francis Favorini (Feb 12)
- Re: ISS Internet Scanner Cannot be relied upon for conclusive Steven M. Christey (Feb 12)
- Re: ISS Internet Scanner Cannot be relied upon for conclusive Daniele Orlandi (Feb 13)
- Re: ISS Internet Scanner Cannot be relied upon for conclusive Shaun Lowry (Feb 15)