Solved

Apache tomcat vulnerabilities

Posted on 2012-03-12
5
342 Views
Last Modified: 2012-04-02
1) As a rough figure how often do Apach release security patches for Tomcat? I.e. per month, per week, how many?

2) And what tools can admins use to ensure that their apache is kept up to date? Do apache provide any free ones?

3) What would auditors look for when reviewing pacth management procedures for non MS software? For example if you did a scan and it said "apache out of date", they may apply a patch and then rescan and its gone, only for next week 5 more patches to come out and then its insecure again, and the process isnt managed.

4) So what demonstrates good patch management, i.e. what visually shows the auditor that this problem wont happen again?
0
Comment
Question by:pma111
  • 3
  • 2
5 Comments
 
LVL 3

Author Comment

by:pma111
Comment Utility
And should a vulnerability assessment/pen test identify "how things came to be so insecure", or is the va/pen test really just to show "this is how insecure how things are, here are the quick fixes, the strategy behind how these are prevented long term is your audit depts problem not us"?
0
 
LVL 26

Accepted Solution

by:
Leon Fester earned 500 total points
Comment Utility
Check the quick downloads section:
http://benchmarks.cisecurity.org/en-us/?route=default
0
 
LVL 3

Author Comment

by:pma111
Comment Utility
Thanks for the benchmark, but I'd still appreciate replies in line with 1-5 posted above for future reference.
0
 
LVL 26

Expert Comment

by:Leon Fester
Comment Utility
Did you even bother to look at the link and download one of the files from this site?

If you did then you'd see a whole lot more than just a 1-5 point.

Here is a snippet of one of the items in the Benchmarks

1.3.3 Lock the Apache User Account (Level 1, Scorable)
:Description
The user account under which Apache runs, should not have a valid password, but should be locked.

Rationale:
As a defense-in-depth measure the Apache user account should be locked to prevent logins, and to prevent a user from su-ing to apache using the password. In general, there shouldn’t
21 | P a g e
be a need for anyone to su as apache. If a need does exist, sudo should be used instead, which would not require the apache account password.

Remediation:
Use the passwd command to lock the apache account: # passwd -l apache

Audit:
Ensure the apache account is locked using the following:
# passwd -s apache
The results will be similar to the following:
apache LK 2010-01-28 0 99999 7 -1 (Password locked.)

Default Value:
The default user is daemon and is locked.

So you've got information to do the following
Describe your problems/issues
Rationale behind the recommendation
Remediation Actions to fix the problem
How to audit
Default values

If you apply the benchmark remediation correctly then you probably won't have many failed audit issues.
0
 
LVL 3

Author Comment

by:pma111
Comment Utility
I did indeed and many thanks, but it would be useful to see how many on average security updates for apache are released per month, and I could find this information.
0

Featured Post

Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

Join & Write a Comment

This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
It’s a strangely common occurrence that when you send someone their login details for a system, they can’t get in. This article will help you understand why it happens, and what you can do about it.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now