|
Title: Remote fixing tool Post by: Hack_80 on May 08, 2012, 07:02:34 AM Hi,
Since i am scaning with nessus tool more than 15000 machines on which i am finding more than 200+ different vulnerabilities. Since i filtered False positive i m finding nearlt 190 odd vulnerabilities. Looking for some automate tools to fix the Nessus reported vulnerabilities remotely. thanks in Advance Title: Re: Remote fixing tool Post by: ajohnson on May 08, 2012, 07:26:59 AM Can you provide any more details, even at a high level (i.e. OS patches, client-side software, OS configuration, etc.)? The types of operating systems would help too since tools and techniques will likely differ between Windows and *nix. Any recommendations are going to depend a great deal on those details.
Title: Re: Remote fixing tool Post by: idr0p on May 08, 2012, 06:23:37 PM You can use SCCM to do patch management. There is also Dell Kace and other tools where a "agent" on the system will issue the updates accordingly.
Title: Re: Remote fixing tool Post by: Hack_80 on May 09, 2012, 06:18:07 AM Hi,
there are vulnerabilities related to settings as well, related to MS patches taken care by Remote deployment tool. Pls find the attached for the details of vuln reported Wondering for the setting issues. Title: Re: Remote fixing tool Post by: unicityd on May 09, 2012, 11:01:47 AM Most of those problems will need to be fixed manually. The list you posted includes multiple applications on multiple operating systems. There's no one script or tool that you can use to fix them all.
Title: Re: Remote fixing tool Post by: cd1zz on May 09, 2012, 01:32:22 PM Sounds like you just need centralized patch management. A lot of those vulns are from missing patches. You might just have a few separate ones, like centralized YUM for example.
Title: Re: Remote fixing tool Post by: 3xban on May 11, 2012, 09:27:55 AM How big is the environment? If it is under 3000 IPs then you can look at something like GFI LANguard, this does vulnerability scanning with patch management. Supports multi-platform and 3rd party applications I believe (from last time I worked with it). Another option is Dell Kace appliance. I've worked with this as well. This supports Mac, Linux and Windows. along with support for 3rd parties, you can create custom install scripts for apps that may not be in their library. Similar to using GPO but I found it to be much cleaner, and again, it supports multiple platforms. I think they are even moving into mobile support for iPads and other types of tablet devices. It works as a decent inventory tool as well.
Powered by SMF 1.1.18 |
SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com |