5 ms·
> And then the next best use of your time and resources is to prioritize the fastest possible patching cadence, since the vast majority of attacks target disclo
by dandrew5 3y ago
> And then the next best use of your time and resources is to prioritize the fastest possible patching cadence, since the vast majority of attacks target disclosed vulnerabilities.
Just curious, do you leverage any tools to decide when to patch or is it time-interval based? We currently attempt[0] to update our packages quarterly but it would be nice to have a tool alert us of known vulnerabilities so we can take action on them immediately.
[0] "Attempt" meaning we can't always upgrade immediately if the latest version contains difficult-to-implement breaking changes or if it's a X.0.0 release that we don't yet trust
- eyegor 3y agoBesides pointing pentester tools like metasploit at yourself, there are some nice scanners out there. Examples in no particular order: https://github.com/quay/clair https://github.com/quay/clair https://github.com/anchore/grype/ https://github.com/anchore/grype/ https://github.com/eliasgranderubio/dagda/ https://github.com/eliasgranderubio/dagda/ https://github.com/aquasecurity/trivy https://github.com/aquasecurity/trivy So then you set up something like a cron job to scan everything for you and email the results once a week or whatever if you don't want to monitor things actively.
- dandrew5 3y agoThanks for these. I should have clarified, I'm more interested in something that will alert me when newly-discovered vulnerabilities surface. The systems I maintain are protected [enough] today but a new hack could drop that doesn't make mainstream media and I may not hear about it. We have annual security audits but it would be nice to patch things immediately. Aside from subscribing to a security forum/discord/slack, I'm wondering what other methods folks are employing to solve this.
- bradknowles 3y agoKeep your pentesting tools up-to-date. Run them against yourself on every single deployment, if you can. Don't just run them quarterly because that's all that your PCI-DSS requirements say you have to do. Integrate security code scanning tools into your CI/CD process. Tools like Dry Run Security, or something comparable. There's much more, but that has to do with how to run your CI/CD systems and how to do your deployments in general, and less to do with security aspects thereof.
- hiStartex 3y agoFor Gentoo: glsa-check --list
- BLKNSLVR 3y agoI just setup GVM / OpenVAS[0] to work out where I need to put in some maintenance work, how does that rate as worthwhile in comparison to those you've listed above? (which I will also look into). (not a fan of the effort Greenbone have gone to for hiding their community edition and promoting their commercial products) [0]: https://greenbone.github.io/docs/latest/22.4/container/index.html https://greenbone.github.io/docs/latest/22.4/container/index...
- layer8 3y agoThe simplest is to only use packages from a distribution like Debian and run unattended-upgrades or equivalent for the security-updates repository. They usually fix vulnerabilities in less than a day.
- snowwrestler 3y agoI’m out of the self-hosting game now, but back in the day we just tried to keep up on security announcements.