3 ms·
My experience in corporate and government is the opposite. They require functional scanning. Always. But they also required expensive functional scammer/scanne
by bitminer 7y ago
My experience in corporate and government is the opposite. They require functional scanning. Always.
But they also required expensive functional scammer/scanner subscriptions. I see this basic tool plus some scraping of changelogs (included in suse and redhat binary rpms) for cve numbers should substantially reduce the false positives. For the price of another 50 lines of python.
Don't know what other distros or the BSDs have available.
- tssva 7y agoWe have had completely opposite experiences then. I have almost never never had a corporate or government entity require a functional scan in a production environment. Some have started off asking for one but in the end I have never had one actually do one. They always end up balking at the need to supply credentials and are uneasy with the risk to the stability of production system inherent in a functional scan. Instead they settle for the non-functional scan from the expensive subscription tools such as Qualys which they use. The majority of time these reports are being produced to fulfill an auditing or FISMA requirement and not considered worth the risk to systems a functional scan could present.