Solved

Internal & External Vulnerability Scans

Posted on 2014-03-02
2
432 Views
Last Modified: 2014-03-23
Hello,

I have a client that runs a medical facility, very small, only about 30 employees & computers. We're looking for an internal and external vulnerability scan program we can run once a quarter to gage the security of our network.

Does anyone have any suggestions?
0
Comment
Question by:SouthernTierGraphics
2 Comments
 
LVL 20

Assisted Solution

by:edster9999
edster9999 earned 250 total points
ID: 39898565
Step 1 - Download a suite like Kali Linux ( http://www.kali.org/ )
That is what used to be called Back Track.  It is linux with a full set of penetration testing utils.

Step 2 - Do not even think about booting it or installing it without training.
There is a lot more to pentesting than having some software.  That would be roughly like saying "I have some diag software on my laptop for my car - I'm going to service it from now on".
Get a 5 day training course and learn what it is, how it works etc.
If money is tight - get a 1 day course,
If money is *really* tight - get a good book and learn from there.
0
 
LVL 27

Accepted Solution

by:
skullnobrains earned 250 total points
ID: 39901883
using a vulnerability scan will not make it much more secure. you'll just end up with a huge bunch of information which mostly will not apply because they will correspond to modules you're not even using or cases that simply could not happen in your setup while you likely have plenty of other things to take care

here are a few security basics
- don't run servers with a user that has unneeded privileges
- don't mix wan-accessible machines with other machines, additionaly use reverse proxies if possible
- educate your users so they do not do foolish things, if not feasible (or additionnally) make them run their machines under restricted accounts
- use a firewall, don't open useless things, use protocol inspection and/or proxies as much as possible
- don't use a domain, or network drives, or any other stuff that will let malware spread from a machine to the next unless you actually need them. if you do need them, learn how to secure each of them
- use antiviruses on the hosts, file servers, mail servers, espetially if you are using windows. if you are using windows, use personnal firewalls and deactivate unneeded services

this is maybe about 20% of the work that needs to be done before you even consider using a vulnerability scanner
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Various banks online banking still use TLSv1.0 : what's acceptable? 5 126
discontiguous network and EIGRP 12 84
Botnet detection help me please 21 134
Structural Sanitization 4 46
Envision that you are chipping away at another e-business site with a team of pundit developers and designers. Everything seems, by all accounts, to be going easily.
This story has been written with permission from the scammed victim, a valued client of mine – identity protected by request.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question