OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: RE: vulnerabilities report for all scanned computers?
From: mark.teichernetworkice.com
Date: Sat Oct 07 2000 - 16:46:05 CDT


TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
majordomoiss.net Contact issforum-owneriss.net for help with any problems!
----------------------------------------------------------------------------

Sounds like a very tedius and manual process. Why not use the tools
available to do it for you. I doubt if this methodology was followed for
a large scale enterprise that manual scanning of two reports stays feasible.

??

At 06:55 AM 10/5/00 -0600, Sabrah Calloway wrote:

>TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
>majordomoiss.net Contact issforum-owneriss.net for help with any problems!
>----------------------------------------------------------------------------
>
>We too, have a requirement to show what machines were actually reached
>during a scan. The following procedure solved the problem for our scanning
>team.
>
>Under the report menu in ISS 6.1, go to technician, operating system. You
>can run a report that shows different information than the vulnerability
>report. If you run this type of report, it will show every machine that ISS
>looked at during your scan, what the operating system was and if it was
>reachable. You can compare this to your vulnerability report. This will give
>a more accurate representation of the scan.
>
>We even go as far as to parse the information from both of the reports and
>combine the results for the true representation for accountability to
>management.
>
>Hope this helps.
>
>Sabrah Calloway
>
>
>-----Original Message-----
>From: owner-issforumiss.net [mailto:owner-issforumiss.net]On Behalf Of
>Thommes, Michael M.
>Sent: Wednesday, October 04, 2000 3:34 PM
>To: 'issforumiss.net'
>Subject: vulnerabilities report for all scanned computers?
>
>
>
>TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
>majordomoiss.net Contact issforum-owneriss.net for help with any
>problems!
>----------------------------------------------------------------------------
>
>Is there are vulnerabilities report in ISS 6.1 that can be generated where
>each computer that was scanned is in the report, even though it might not
>have any vulnerabilities? It seems that all the reports that are available
>only indicate computers where a vulnerability was found. Thanks in advance.
>
>Mike Thommes
>Systems Administrator
>Argonne National Laboratory