Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

Website and Server Administration Forum


You are currently viewing our Website and Server Administration Forum as a guest. Please register to participate.
Login



Reply
Web Application Firewall/Security audit question
Old 03-06-2012, 07:57 AM Web Application Firewall/Security audit question
abrodski's Avatar
Novice Talker

Posts: 10
Name: Al
Trades: 0
Hello!

I run a Joomla site and I went to one of the famous commercial sites that deal with vulnerabilities. They have a free security audit for malware.
I ran it on my site. And I got a reply that "Host is not alive". I have Admin Tools WAF turned ON. They recommend to shut it down temporarily, so their scanner can check everything. But to me that doesn't make any sense. Because, in my opinion, if their scanner couldn't get through, it means that the site passed the audit fine.
abrodski is offline
Reply With Quote
View Public Profile
 
 
Register now for full access!
Old 03-06-2012, 09:49 AM Re: Web Application Firewall/Security audit question
chrishirst's Avatar
Defies a Status

Posts: 43,968
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
Quote:
if their scanner couldn't get through, it means that the site passed the audit fine.
Nope it means the firewall blocked their scanner agent, that does NOT mean that there is no vulnerabilities.
__________________
Chris. ->>
Please login or register to view this content. Registration is FREE
<<-

A foolish consistency is the hobgoblin of little minds
Thought for today:- Is SEO the only industry where all the cowboys are Indians?
chrishirst is online now
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Old 08-30-2012, 06:15 AM Re: Web Application Firewall/Security audit question
Novice Talker

Posts: 12
Trades: 0
Beware that free audit services are created just to attract potential customers. Based on my own experience I wouldn't suggest using them (or at least – not them alone).

Also keep in mind that any automatic scanning engine is not as good as a real security expert. If you have Joomla site, I would suggest first going all the security hardening steps (recent versions, updated components and plugins, secure FTP, restricted access and so on). Only then you should test website security with professional company. I recommended www.webyfly.com for a couple of my customers as an first measure. As I know they do automatic testing, but real humans fine tune-the tools and analyze the results.

Also you could periodically check unmaskparasites.com for all the nasty things already in your site.
DeividasS is offline
Reply With Quote
View Public Profile
 
Reply     « Reply to Web Application Firewall/Security audit question
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.16534 seconds with 11 queries