Re: [CentOS] Recommendation for a Good Vulnerability Scanning Service?

2011-02-20 Thread Ian Forde
On Fri, 2011-02-18 at 15:09 -0500, Michael B Allen wrote: Are you talking about the SAQC? I run all CC transactions through one CentOS VPS webserver (actually I have two servers that I periodically wipe out and alternate between every year or two). So I don't have POS terminals or any Windows

Re: [CentOS] Recommendation for a Good Vulnerability Scanning Service?

2011-02-20 Thread Ian Forde
On Fri, 2011-02-18 at 15:51 -0500, John Hinton wrote: Very good information, Ed. And yes, you will almost certainly be fighting with the compliance company, as I have not yet seen any who recognized CentOS. RHEL, yes. CentOS however does not hold the same 'trusted standard' or clout as the

Re: [CentOS] Recommendation for a Good Vulnerability Scanning Service?

2011-02-20 Thread Michael B Allen
On Sun, Feb 20, 2011 at 6:58 PM, Ian Forde ianfo...@gmail.com wrote: On Fri, 2011-02-18 at 15:09 -0500, Michael B Allen wrote: Are you talking about the SAQC? I run all CC transactions through one CentOS VPS webserver (actually I have two servers that I periodically wipe out and alternate

[CentOS] Recommendation for a Good Vulnerability Scanning Service?

2011-02-18 Thread Michael B Allen
Hi, Can someone recommend a good vulnerability scanning service? I just need the minimum for PCI compliance (it's a sort of credit card processing certification). I got a free scan from https://www.hackerguardian.com/ and their scan reported a number of Fail results. I haven't checked them all

Re: [CentOS] Recommendation for a Good Vulnerability Scanning Service?

2011-02-18 Thread Baird, Josh
We use Qualys for PCI vulnerability scanning. Josh -Original Message- From: centos-boun...@centos.org [mailto:centos-boun...@centos.org] On Behalf Of Michael B Allen Sent: Friday, February 18, 2011 1:20 PM To: centos@centos.org Subject: [CentOS] Recommendation for a Good Vulnerability

Re: [CentOS] Recommendation for a Good Vulnerability Scanning Service?

2011-02-18 Thread m . roth
Hi, there, Michael B Allen wrote: Can someone recommend a good vulnerability scanning service? I just need the minimum for PCI compliance (it's a sort of credit card processing certification). Sort of? ROTFL. You need a *serious* scan, commercially done AFAIK. The *minimum* qualifications, I

Re: [CentOS] Recommendation for a Good Vulnerability Scanning Service?

2011-02-18 Thread Michael B Allen
On Fri, Feb 18, 2011 at 2:36 PM, m.r...@5-cent.us wrote: Hi, there, Michael B Allen wrote: Can someone recommend a good vulnerability scanning service? I just need the minimum for PCI compliance (it's a sort of credit card processing certification). Sort of? ROTFL. You need a *serious*

Re: [CentOS] Recommendation for a Good Vulnerability Scanning Service?

2011-02-18 Thread Dr. Ed Morbius
on 14:20 Fri 18 Feb, Michael B Allen (iop...@gmail.com) wrote: Hi, Can someone recommend a good vulnerability scanning service? I just need the minimum for PCI compliance (it's a sort of credit card processing certification). First: if you're headed down the compliance / certification

Re: [CentOS] Recommendation for a Good Vulnerability Scanning Service?

2011-02-18 Thread Brian Mathis
On Fri, Feb 18, 2011 at 2:20 PM, Michael B Allen iop...@gmail.com wrote: Hi, Can someone recommend a good vulnerability scanning service? I just need the minimum for PCI compliance (it's a sort of credit card processing certification). I got a free scan from https://www.hackerguardian.com/

Re: [CentOS] Recommendation for a Good Vulnerability Scanning Service?

2011-02-18 Thread m . roth
Dr. Ed Morbius wrote: on 14:20 Fri 18 Feb, Michael B Allen (iop...@gmail.com) wrote: Can someone recommend a good vulnerability scanning service? I just need the minimum for PCI compliance (it's a sort of credit card processing certification). snip I'd suggest you educate yourself on the PCI

Re: [CentOS] Recommendation for a Good Vulnerability Scanning Service?

2011-02-18 Thread John Hinton
On 2/18/2011 3:09 PM, Dr. Ed Morbius wrote: I haven't spoken with the hackerguardian people yet but it would be nice if I could just say I'm using CentOS 5.5 and have them factor that into their report so that I can focus on any real issues. Are there vulnerability scanning services that are

Re: [CentOS] Recommendation for a Good Vulnerability Scanning Service?

2011-02-18 Thread m . roth
John Hinton wrote: On 2/18/2011 3:09 PM, Dr. Ed Morbius wrote: I haven't spoken with the hackerguardian people yet but it would be nice if I could just say I'm using CentOS 5.5 and have them factor that into their report so that I can focus on any real issues. Are there vulnerability

Re: [CentOS] Recommendation for a Good Vulnerability Scanning Service?

2011-02-18 Thread John Jasen
On 02/18/2011 03:09 PM, Michael B Allen wrote: Hackerguiardian is a commercial service (it's actually COMODO CA Limited). Their scan looks thorough. Obviously they're just matching up version numbers with CVE notices but I have a feeling most of these guys are going to be doing the same

Re: [CentOS] Recommendation for a Good Vulnerability Scanning Service?

2011-02-18 Thread Eero Volotinen
2011/2/18 John Hinton webmas...@ew3d.com: On 2/18/2011 3:09 PM, Dr. Ed Morbius wrote: I haven't spoken with the hackerguardian people yet but it would be nice if I could just say I'm using CentOS 5.5 and have them factor that into their report so that I can focus on any real issues. Are