Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: We Found the Vulnerabilities, so What Next ?!! |
|---|---|
| Date: | Fri, 17 Feb 2006 18:51:33 +0300 |
Dear chmod077, I'm not saying this is an nessus issues, I post my question her because I think some of you face this issues. Yes that right, hardening the system is the best solution, but if we talk about the case in general, should the system have 0 vulnerability ? I mean is it an important to patch the system even if this vulnerability can't be exploited remotely ? Lets say we have a web server, and it is in zone with only port 80 is opened. So, when we scan the system we found a lot of vulnerabilities, but there is 0 vulnerability related to the web service. The only way to reach the system is be using port 80, even the Administrator should go to the system (physically) and do his job. and we trust the admin :-). Is it important (in this case) to patch the system? is the high vulnerabilities that we discovered is really a high ? can we say its medium or low now, since it not related to port 80 service ? Regards, On 2/17/06, chmod077@gmx.de <chmod077@gmx.de> wrote:
Dear Mansour, in my opinion the easiest way to solve your problem is something like rpm -e "unused package" The other thing is: It is an administrators task to decide to patch or to patch not the special vulnerability ..... If in doubt : patch. If there are some problems concerning rpms and unsolved dependencies: It is not a nessus problem. Please, read about installing packages using rpm.... regards chmod077.
_______________________________________________ Nessus mailing list Nessus@list.nessus.org http://mail.nessus.org/mailman/listinfo/nessus
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: NASL Errors at Startup, Renaud Deraison |
|---|---|
| Next by Date: | Re: We Found the Vulnerabilities, so What Next ?!!, Renaud Deraison |
| Previous by Thread: | Re: We Found the Vulnerabilities, so What Next ?!!, chmod077 |
| Next by Thread: | Re: We Found the Vulnerabilities, so What Next ?!!, Renaud Deraison |
| Indexes: | [Date] [Thread] [Top] [All Lists] |