Product identification can be incomplete
Banners may omit versions, be intentionally changed or reflect a proxy rather than the backend application.
A matching version is not the same as proven exploitability
A CVE may apply only to a component, configuration, platform or feature that cannot be established from outside.
Context is still useful
If public evidence strongly suggests an outdated exposed product, that is a valid reason for the owner to verify the actual version internally.
Online treats CVE information as assessment context
Scantide Online can add CVE-related context where product evidence supports it, while keeping the observation separate from claims of successful exploitation.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: Public Server Security AssessmentUse Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.
Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web ExposureScantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.
Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web ExposureUse Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.
Current Scantide source: DNS, SPF and DMARC Security CheckerScantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.
Current Scantide source: External Attack Surface Assessment and DiscoveryExternal attack surface work begins with visibility: which hosts answer, which services are exposed and which systems appear to belong to the organization.
Field experience from the archive
Historical source · JufCorp: Securing your server environment – part I – Physical environmentKnow where your backups are, at all times. Have them encrypted. If using online backup services, be sure to use an encryption key and , if possible, be sure to have restrictions on the online backup service providers end on to and from where backups and restores are allowed
Historical source · JufCorp: Securing your servers, users and customers onlineA 0day is a security bug in the software of the server your running and they vary on how much impact they may have. The name comes from that it is day 0 of it's public release and the manufacturer, in this case Microsoft, hasn't released any patch against it leaving you vulnerable no matter what you do. Some of them are even just a nifty way of adding stuff (specific strings ) to the URL or the service the attacker wants to reach and bypassing all of the built in security by "fooling" the server. Whatever they do, keep track of when they surface and see what can be done to mitigate them.
Remember to check your mail queues on a regular basis If you're starting to have loads of undelivered mail to and from various domains you could actually have a DNS server that's under attack , not being able to service your Exchange server with required information .
Also, as a complement, use an online service also that filters all of your incoming and outgoing mail from viruses and SPAM and also have you secondary MX records point to it. Usually these services also hold you mail in queue if they cant' be delivered, buying you time to change the IP addresses or server if you are under attack and not losing any mails.
Historical source · JufCorp: Juha JurvanenInitiator of the brute force protection software , Syspeace. Juha had the original idea and the project entailed testing, verifying, adding features. On top of that writing technical articles and raising awareness online. The product is now a commercial product publically available but I'm sadly no longer part of it . I woud love to but sadly that's not what it is today. Syspeace was "my baby" and now I don't get anything for it, sad to say.
Historical source · JufCorp: Securing your server environment - Part III - Operating systemsWhatever you'll be using your server for. have a look at any information that it "bleeds". This could for instance be headers telling any attacker exactly what version of software you're running. If possible, try to hide such information. There's no need for it to be visible and help a hacker find a way in. Simple checks using telnet to the ports your services might reveal some interesting information . Sadly, it's not possible to remove all headers etc but you should give it a go and remove as many as possible While on the subject, use SSL-certificates for any service where possible. Also make sure to set it up correctly (disable weak ciphers, enable HSTS, set correct HTTP headers, set TLS correctly etc ) . Have a look at Letsencrypt for instance for SSL certificates. It's free, supported by basically everyone and it'll probably get the job done for you . All you have to remember is to check that your certificates are renewed every three months.
Practical review checklist
- Use Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.
- Scantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.
- Use Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.
- Scantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.
- External attack surface work begins with visibility: which hosts answer, which services are exposed and which systems appear to belong to the organization.
- A 0day is a security bug in the software of the server your running and they vary on how much impact they may have.
- Initiator of the brute force protection software , Syspeace.