In security community, there is a common used standard to evaluate a patch or a vulnerability called CVSS. Many product vendors such as Cisco use it to give a score for patch of their product, and also security service vendors such as Nessus, Qualys and IBM ISS also use CVSS to calculate a score for patch when supporting their vulnerability scanner, IDS, or patch notification service delivery.
So here comes the problem. For a certain Microsoft patch, Microsoft uses its own rating method to give a severity rating, usually rated as Critical or Important. Security vendors can not just copy this rating because Critical patches are too often from Microsoft and they are not as so Critical as they appear. So other vendors create their own rating method too or just follow CVSS. Of course we can guess the result now: different vendors have different rating for the same patch! I don’t want to show examples here because everyone knows that.
Let’s back to enterprise environment, security team delivers patches with their severity rating. How could the rating be accurate because the community has different ratings around? In my opinion, only most critical vulnerabilities should be considered as High or Urgent rating, such as MS04-011 and MS08-067, which could lead system been took over easily by script kids and automatic worms. For other patches, should be considered as Medium or Low depends on its mechanism, no accuracy needed between Medium and Low. Operations team just needs to focus on High severity patches which could affect company business. This should be defined in company security policy with different time frame requirement. So policy maker should understand these facts to write proper policy make operations team’s life easier.
Showing posts with label Vulnerability. Show all posts
Showing posts with label Vulnerability. Show all posts
Friday, March 13, 2009
Tuesday, January 6, 2009
CVSS2 Base Score Offline Calculator
On FiRST site only v1 offline calc can be found, and all v2 calc are provided as online now. So I modified the v2 excel calc from the v1 one with new equation, but it still took me 2 hours to make it.

Wednesday, December 3, 2008
McAfee Foundstone Enterprise Tryout
Foundstone is famous for its free security tools, such as fport, superscan and sqlscan. Long time ago the company started providing assessment service with their own assessment software, but even after it was acquired by McAfee, this software was not available on public.
Now McAfee are selling their appliance with vulnerability scanning and management software preinstalled, it’s impossible for a download and a try. Fortunately on Nov 28 the formerly Foundstone Enterprise software was released in 0day scene*, so I have a chance to try it.
After tryout of a whole day, I had to say that it’s really a true vulnerability management platform for large scale corporations. I’d suggest buying the appliance if we have budget.
From the installation I found it’s a product designed by security guys. The windows and database are required to have proper SP installed, new added assets admin password is forced to be strong, otherwise you cannot finish the configuration. Signatures updating is required to input username and password, which will help manage license and forbid pirate version usage. It’s a security product, why not?
Like other SaaS vendors such as IBM and Qualys, Foundstone has a web portal too, which provide assets management, vulnerability scanning, reporting and remediation. Here I list some functions that I think they are highlights of foundstone.
Assets are grouped by BU, echo group is assigned with an admin. Scans can be implemented by business function, asset value, owner or location. Security team could focus on the most valued assets easily.
Lots of scan templates, includes ISO17799, NIST SP800-68, SOX, PCI and wireless, etc.
Immediately verify that whether the vulnerability has been fixed or not, by examining the system in ticket management with a single click. This makes fix tracking damn efficiently! No need to launch new scan, or verify with other tools.



Now McAfee are selling their appliance with vulnerability scanning and management software preinstalled, it’s impossible for a download and a try. Fortunately on Nov 28 the formerly Foundstone Enterprise software was released in 0day scene*, so I have a chance to try it.
After tryout of a whole day, I had to say that it’s really a true vulnerability management platform for large scale corporations. I’d suggest buying the appliance if we have budget.
From the installation I found it’s a product designed by security guys. The windows and database are required to have proper SP installed, new added assets admin password is forced to be strong, otherwise you cannot finish the configuration. Signatures updating is required to input username and password, which will help manage license and forbid pirate version usage. It’s a security product, why not?
Like other SaaS vendors such as IBM and Qualys, Foundstone has a web portal too, which provide assets management, vulnerability scanning, reporting and remediation. Here I list some functions that I think they are highlights of foundstone.
Vulnerability management is a program with tools and processes. Many security vendors are selling their service today, with 7x24 supports. For enterprise environment, the single scanner software is dead now.
*The scene version is a 60 days trial one, no password provided for online updating.
Screenshots in my tryout, click for large view:

Thursday, November 6, 2008
Vulnerability Management with MS08-067
It’s already 2 weeks since Microsoft released patch for MS08-067. The company I am working for has already patched 88% windows servers in the first week, and till now, 98% servers were patched.
This time frame is well compliant with company security policy, and here I have some experience to share after this urgent patching period.
First of all, for a vulnerability management program, assets management is the most important. Asset inventory should be centralized and well maintained, the scope can be identified in first step, then all assigned owners and custodians will be notified immediately. This will speed up patch progress, especially for DMZ servers which are facing threats from internet.
Secondly, a well established patch process is needed, which should be effective in such urgent situation. Usually ops team has to submit change request to get change windows to perform patching task, but for urgent patch issue, there should be special process to gain support from upper management, pushing jobs done quickly.
Thirdly, security team should be armed with some tools, to identify vulnerability, check patch status, or exploit vulnerability for demonstration purpose. Except the commercial software our company bought, here I recommend the free Metasploit Framework that everyone can download freely. Metasploit is an open platform to do penetration test and vulnerability research. The project team was updating ms08-067 scanner and exploit in daily snapshot, we could finish the cycle of identification, assessment, checking and monitor in ms08-067 patch management easily.
This time frame is well compliant with company security policy, and here I have some experience to share after this urgent patching period.
First of all, for a vulnerability management program, assets management is the most important. Asset inventory should be centralized and well maintained, the scope can be identified in first step, then all assigned owners and custodians will be notified immediately. This will speed up patch progress, especially for DMZ servers which are facing threats from internet.
Secondly, a well established patch process is needed, which should be effective in such urgent situation. Usually ops team has to submit change request to get change windows to perform patching task, but for urgent patch issue, there should be special process to gain support from upper management, pushing jobs done quickly.
Thirdly, security team should be armed with some tools, to identify vulnerability, check patch status, or exploit vulnerability for demonstration purpose. Except the commercial software our company bought, here I recommend the free Metasploit Framework that everyone can download freely. Metasploit is an open platform to do penetration test and vulnerability research. The project team was updating ms08-067 scanner and exploit in daily snapshot, we could finish the cycle of identification, assessment, checking and monitor in ms08-067 patch management easily.
Monday, October 27, 2008
Test of MS08-067 exploit
Subscribe to:
Posts (Atom)