Re: Handling new vulnerabilities like WebDav

Jose Nazario <[email protected]> Thu, 20 Mar 2003 12:29:22 -0500 (EST)
Newsgroups gmane.comp.security.incident-handling
Message-ID <[email protected]>
On Thu, 20 Mar 2003, Darren Van Booven wrote:

> For me, the most time is spent determining whether or not the
> vulnerability is really a risk or not out of the hundreds of other
> security alerts issued each week.

i posted a few links on this topic in a story last fall on deadly.org:

	http://www.deadly.org/article.php3?sid=20021117160433

in a nutshell the presumption for most of these people is that no exploit
yet exists for the service. here, the process was reversed, the vuln was
identified and fixed after the exploit was in use.

obviously some additional info is going to be needed on how to properly
identify which systems are vulnerable to this issue and which are not. but
darren's right, scan, identify, and shut the service feature off, filter
the host at an apppriate network point, and remedy with the patch as soon
as possible.

___________________________
jose nazario, ph.d.			[email protected]
					http://www.monkey.org/~jose/