hi folks ,
i am new to the security arena.

We just installed FW1 at our office.

Now we want to do a local network Audit. Could u suugest some tools etc.
Also how to get rid of the vulnerabilities

<psh>
Try nessus http://www.nessus.org for a free tool, its great also Sara
http://www-arc.com.  If your company wants one that it has to pay for I
would go with eeye's Retina http://www.eeye.com.  If it is a windows
network and you want to do a NetBIOS audit you could use LanGuard
http://www.gfi.com/languard/lanscan.htm (the new version does most of
the Unix systems as well as SNMP audits)  I have a list of several
others on my website. Under "Security Assessment"
(www.internetsecurityguru.com)
</psh>


Also we have setup a web server and wanna know, which tool to  audit its
vulnerablilities and how to get rid of the vulnerabilities.

<psh>
Download the trial of Retina from eeye and try Nessus.  They are both
great.  If you don't know and *nix the eeye product will be better for
you.

When whatever program you use identifies the vulnerability it will
usually link to a page that talks about fixing it.  If not go to either
the vendor sight or the indispensable www.google.com and search for the
vulnerability.

Of course you could also hire an infosec professional to come in and do
the audit and some training as well.  I don't know what city your in but
I'm sure someone on this list can suggest a firm in that city.
</psh>


ALok

Reply via email to