Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Incidents: Re: IIS Exploit...

Re: IIS Exploit...

From: Brian Caswell <bmc_at_MITRE.ORG>
Date: Wed, 9 May 2001 08:47:33 -0400

Chris Hobbs wrote:
>
> Well, not too much info here - regrettably my snort rules file got
> zeroed out when whitehats.com changed their format. So, all I have is my
> IIS logs - however, it's pretty straightforward what happened:

YET ANOTHER REASON NOT TO AUTOMAGICLY UPDATE YOUR RULESET!!!!!!!!!

Geez. I don't know how many times I have to say this. Automagicly
downloading rulesets for ANYTHING is a very DUMB idea. If you are
deploying anything like this and you want automagic updates to your
sensors, at LEAST pull your rules from a LOCALLY administrated copy.
And update the LOCAL copy by hand.

-brian
Received on May 11 2001

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos