RE: Handling new vulnerabilities like WebDav - SUMMARY
<[email protected]> Tue, 25 Mar 2003 13:12:24 -0500
| Newsgroups | gmane.comp.security.incident-handling |
|---|---|
| Message-ID | <[email protected]> |
Minus the vendor plugs, here is a summary of the information I received = on this thread in no particular order: 1. Maintain an accurate inventory of your assets to include, OS, = platform, applications, patch levels, services etc.. This can then be = used to quickly identify your risk in relation to a new vulnerability. = As mentioned by several folks, this is extremely difficult and time = consuming. 2. Use a preventative IDS solution to prevent the attack and then patch = at your leisure. 3. Run an immediate scan of your environment to determine your risk. = Then patch, or implement mitigating controls based on the results. = Possibly use your ticketing system to create accountability, or send = emails to those accountable. Bob=20 ----- Original Message ----- From: <[email protected]> To: <[email protected]> Sent: Thursday, March 20, 2003 9:49 AM Subject: Handling new vulnerabilities like WebDav > I am curious as to how people in large organizations are handling new vulnerabilities like the WebDAV recently released. Specifically, I'm = trying to gauge how people are determining their exposure, or risk level. Upon learning of a new vulnerability are folks scanning their entire = environment to look for the vulnerability? Or are folks going through their = inventory to look for IIS web servers and having folks manually check them? > > Just looking for input. Please reply directly to me and I will sum up = and post. > > Thanks, > > Bob > > > ********************************************************************** > This transmission may contain information that is privileged, = confidential and/or exempt from disclosure under applicable law. If you are not the intended recipient, you are hereby notified that any disclosure, = copying, distribution, or use of the information contained herein (including any reliance thereon) is STRICTLY PROHIBITED. If you received this = transmission in error, please immediately contact the sender and destroy the material = in its entirety, whether in electronic or hard copy format. Thank you > ********************************************************************** > >