RE: Handling new vulnerabilities like WebDav - SUMMARY

<[email protected]> Tue, 25 Mar 2003 13:12:24 -0500
Newsgroups gmane.comp.security.incident-handling
Message-ID <[email protected]>
Minus the vendor plugs, here is a summary of the information I received =
on this thread in no particular order:

1.  Maintain an accurate inventory of your assets to include, OS, =
platform, applications, patch levels, services etc..  This can then be =
used to quickly identify your risk in relation to a new vulnerability.  =
As mentioned by several folks, this is extremely difficult and time =
consuming.

2.  Use a preventative IDS solution to prevent the attack and then patch =
at your leisure.

3.  Run an immediate scan of your environment to determine your risk.  =
Then patch, or implement mitigating controls based on the results.  =
Possibly use your ticketing system to create accountability, or send =
emails to those accountable.

Bob=20


----- Original Message -----
From: <[email protected]>
To: <[email protected]>
Sent: Thursday, March 20, 2003 9:49 AM
Subject: Handling new vulnerabilities like WebDav


> I am curious as to how people in large organizations are handling new
vulnerabilities like the WebDAV recently released.  Specifically, I'm =
trying
to gauge how people are determining their exposure, or risk level.  Upon
learning of a new vulnerability are folks scanning their entire =
environment
to look for the vulnerability?  Or are folks going through their =
inventory
to look for IIS web servers and having folks manually check them?
>
> Just looking for input.  Please reply directly to me and I will sum up =
and
post.
>
> Thanks,
>
> Bob
>
>
> **********************************************************************
> This transmission may contain information that is privileged, =
confidential
and/or exempt from disclosure under applicable law. If you are not the
intended recipient, you are hereby notified that any disclosure, =
copying,
distribution, or use of the information contained herein (including any
reliance thereon) is STRICTLY PROHIBITED. If you received this =
transmission
in error, please immediately contact the sender and destroy the material =
in
its entirety, whether in electronic or hard copy format. Thank you
> **********************************************************************
>
>