Penn Computing

Penn Computing

Computing Menu Computing A-Z
Computing Home Information Systems & Computing Penn

 

Tuesday, November 24, 2009

 
  Security "Greatest Hits"
Managing Passwords
E-mail Harassment & Forgery
Hoaxes, frauds & scams
Spam
Phishing
Wireless Networking
Encryption & digital signatures
 
  Best Practices
Secure desktop computing
Secure servers
Secure web applications
Secure web development
Secure data deletion
Tips for safe computing
Computing policies
 
  More in-depth information for
Local support providers
System administrators
Application developers
 
  Security initiatives
Critical host compliance
Authentication & authorization
Penn Security & Privacy Assessment (SPIA)
Security Liaisons (Restricted Access)
Secure Share
NeXpose Vulnerability Scanner
 
  Related links
Electronic privacy
PennKey
Viruses
Worms, trojans, backdoors

Scan Templates

NameDescriptionDevice DiscoveryService DiscoveryChecks
Custom Exhaustivemore threads, syn scan, more port scans, no device discoveryDisabledFull TCP, Default UDPSafe Only
Denial of servicePerforms a basic network audit of all systems using both safe and unsafe (denial-of-service) checks. In-depth patch/hotfix checking, policy compliance checking, and application-layer auditing will not be performed.ICMP, TCPDefault TCP, Default UDPCustom
DHCPTrying to come up with a discovery that would allow identifying DHCP servers.ICMP, TCP, UDPCustom UDPDisabled
Discovery ScanPerforms a discovery scan to identify live devices on the network, including host name and operating system. No further enumeration, policy or vulnerability scanning will be performed.ICMP, TCP, UDPCustom TCP, Custom UDPDisabled
Discovery Scan - AggressivePerforms a fast and cursory discovery scan to identify live devices on high speed networks, including host name and operating system. Packets are sent at a very high rate which may trigger IPS/IDS sensors, SYN flood protection and exhaust states on stateful firewalls. No further enumeration, policy or vulnerability scanning will be performed.ICMP, TCP, UDPCustom TCP, Custom UDPDisabled
ExhaustivePerforms an exhaustive network audit of all systems and services using only safe checks, including patch/hotfix checking, policy compliance checking, and application-layer auditing. Performing an exhaustive audit could take several hours or even days to complete, depending on the number of hosts selected.ICMP, TCPFull TCP, Default UDPSafe Only
Full auditPerforms a full network audit of all systems using only safe checks, including network-based vulnerabilities, patch/hotfix checking, and application-layer auditing. Only default ports are scanned, and policy checking is disabled, making this faster than the Exhaustive scan.ICMP, TCPDefault TCP, Default UDPCustom
Full audit, no web spideringPerforms a full network audit of all systems using only safe checks, including network-based vulnerabilities, patch/hotfix checking, and application-layer auditing. Only default ports are scanned, and policy checking is disabled, making this faster than the Exhaustive scan.ICMP, TCPDefault TCP, Default UDPCustom
HIPAA compliancePerforms a HIPAA audit of all systems using only safe checks. Settings appropriate for auditing compliance will be enabled as per HIPAA section 164.312 ("Technical Safeguards"). Any conditions resulting in inadequate access control, inadequate auditing, loss of integrity, inadequate authentication, or inadequate transmission security (encryption) will be flagged.ICMP, TCPDefault TCP, Default UDPSafe Only
Internal Fast Full AuditMore threads, port scans, no-web spideringDisabledDefault TCP, Default UDPCustom
Internet DMZ auditPerforms an in-depth penetration test of public-facing servers. All common internet services will be scanned, including web, FTP, mail (SMTP/POP/IMAP/Lotus Notes), DNS, database, telnet, SSH, and VPN services. In-depth patch/hotfix checking and policy compliance audits will not be performed.DisabledDefault TCPCustom
Linux RPMsPerforms an audit of Linux systems for the proper installation of RPM patches. For greatest success, administrative credentials should be used when performing Linux RPM scans.ICMP, TCPCustom TCPCustom
Microsoft hotfixPerforms an audit of Microsoft Windows systems for the proper installation of hotfixes and service packs. For greatest success, administrative credentials should be used when performing Microsoft hotfix scans.ICMP, TCPCustom TCPCustom
Payment Card Industry (PCI) auditPerforms a Payment Card Industry (PCI) compliance audit of all systems using only safe checks, including network-based vulnerabilities, patch/hotfix checking, application-layer auditing, and checks for potential vulnerabilities. All TCP ports are scanned along with well-known UDP ports. Policy checking is disabled.ICMP, TCPFull TCP, Default UDPCustom
Penetration testPerforms an in-depth penetration test of all systems using only safe checks. Host-discovery and network penetration options will be enabled, allowing NeXpose to dynamically discover additional systems in your network to target. In-depth patch/hotfix checking, policy compliance checking, and application-layer auditing will not be performed.ICMP, TCPDefault TCP, Default UDPCustom
Safe network auditPerforms a non-intrusive network audit of all systems using only safe checks. In-depth patch/hotfix checking, policy compliance checking, and application-layer auditing will not be performed.ICMP, TCPDefault TCP, Default UDPCustom
Sarbanes-Oxley compliancePerforms a Sarbanes-Oxley (SOX) audit of all systems using only safe checks. The SOX compliance audit will highlight threats to digital data integrity, data access auditing, accountability, and availability, as mandated in Section 302 ("Corporate Responsibility for Fiscal Reports"), Section 404 ("Management Assessment of Internal Controls"), and Section 409 ("Real Time Issuer Disclosures") respectively.ICMP, TCPDefault TCP, Default UDPSafe Only
Web auditPerforms an audit of all web servers and web applications. Suitable for scanning both public-facing and internal web servers, including application servers, ASP's, CGI scripts, etc. Patch checking and policy compliance audits will not be performed. Note that the Web Audit will not scan FTP servers, mail servers, or database servers. For that, you may want to use the Internet DMZ Audit instead.DisabledDefault TCPCustom

Last updated: Friday, March 20, 2009

top

Information Systems and Computing
University of Pennsylvania
Comments & Questions


Penn Computing University of Pennsylvania
Information Systems and Computing, University of Pennsylvania