﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Ipswitch Forums / Ipswitch Products / WhatsUp Gold  / WUG fails WebInspect scans... / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Ipswitch Forums</description><link>http://forums.ipswitch.com/</link><webMaster>forums@ipswitch.com</webMaster><lastBuildDate>Tue, 07 Oct 2008 01:28:50 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: WUG fails WebInspect scans...</title><link>http://forums.ipswitch.com/Topic43647-14-1.aspx</link><description>Ok,&lt;/P&gt;&lt;P&gt;You will be happy to know that you can use snmp to monitor windows services : &lt;A class=SmlLinks href="http://forums.ipswitch.com/Topic20001-14-1.aspx" target='_"blank"'&gt;http://forums.ipswitch.com/Topic20001-14-1.aspx&lt;/A&gt; (thanks to MB-NS for finding back that one :) )&lt;/P&gt;&lt;P&gt;And, well, indeed, I was about to tell you : if you don't need to acces the wug box from the web, then your security folks can simply deny that traffic, and it does not matter too much whether it's vulnerable or not then...</description><pubDate>Wed, 11 Jun 2008 10:26:50 GMT</pubDate><dc:creator>Sergio</dc:creator></item><item><title>RE: WUG fails WebInspect scans...</title><link>http://forums.ipswitch.com/Topic43647-14-1.aspx</link><description>I believe RPC is required for WhatsUp to interrogate Windows Services.  I have been told there is no way RPC will be opened and so that means the only way to get the Services monitored is to place a WhatsUp box in our DMZ.  The appraoch I am taking now is that I asked our Information Security team if they will allow WhatsUp in our DMZ if only the Operations folks IP addresses can see the WhatsUp website.</description><pubDate>Wed, 11 Jun 2008 09:24:40 GMT</pubDate><dc:creator>kemerick</dc:creator></item><item><title>RE: WUG fails WebInspect scans...</title><link>http://forums.ipswitch.com/Topic43647-14-1.aspx</link><description>Kyle, unless you don't want to monitor your internal boxes, I think it's better to leave wug on the lan and open the relevant ports towards the dmz, rather than the other way around... Your system is probably more likely to be compromised if it's in the dmz, and if compromised and you opened ports towards the lan to allow for monitoring, well...&lt;/P&gt;&lt;P&gt;Not to mention that you (possibly ?) have more hosts inside than on the dmz, so you would need to open towards lots of machines instead of towards a few ones... ?</description><pubDate>Fri, 06 Jun 2008 09:35:14 GMT</pubDate><dc:creator>Sergio</dc:creator></item><item><title>RE: WUG fails WebInspect scans...</title><link>http://forums.ipswitch.com/Topic43647-14-1.aspx</link><description>Right now our Intranet WhatsUp server can only monitor ping on our DMZ servers.  We would like to be able to monitor some of the servers services also.</description><pubDate>Fri, 06 Jun 2008 09:11:00 GMT</pubDate><dc:creator>kemerick</dc:creator></item><item><title>RE: WUG fails WebInspect scans...</title><link>http://forums.ipswitch.com/Topic43647-14-1.aspx</link><description>What's the benefit of putting on the dmz?</description><pubDate>Wed, 28 May 2008 15:53:08 GMT</pubDate><dc:creator>DaveCarlton</dc:creator></item><item><title>RE: WUG fails WebInspect scans...</title><link>http://forums.ipswitch.com/Topic43647-14-1.aspx</link><description>Sounds good to me.  I will try some of these things out and run them by our Information Security folks.  Thank you for your time.</description><pubDate>Wed, 28 May 2008 14:04:59 GMT</pubDate><dc:creator>kemerick</dc:creator></item><item><title>RE: WUG fails WebInspect scans...</title><link>http://forums.ipswitch.com/Topic43647-14-1.aspx</link><description>We used to get this all the time from our security guy and 99% of these are false positives. I'm not in a position to evaluate the cross-site scripting attacks being valid or not but the other two errors are meaningless.&lt;/P&gt;&lt;P&gt;Unhandled exception? Eh.. big deal. The suggestion is to place use uniform error codes or informational error messages doesn't strike me as a security issue. &lt;/P&gt;&lt;P&gt;The http for logins? Click the SSL checkbox. &lt;/P&gt;&lt;P&gt;Personally, if it's that big of an issue you can restrict via IP who has access to the server. &lt;/P&gt;&lt;P&gt;Mike </description><pubDate>Mon, 12 May 2008 12:06:51 GMT</pubDate><dc:creator>cohmike</dc:creator></item><item><title>WUG fails WebInspect scans...</title><link>http://forums.ipswitch.com/Topic43647-14-1.aspx</link><description>In order to get WUG into our DMZ, we first need to have it pass a WebInspect scan.  The scan results were sent to Ipswitch months ago but their repsonse was "see if the next version passes".  I installed version 12 and no dice.&lt;/P&gt;&lt;P&gt;Is there a way I can fix these errors?  If not, if enough of us complain they may fix all the security vulnerabilities within their application...</description><pubDate>Fri, 09 May 2008 14:20:18 GMT</pubDate><dc:creator>kemerick</dc:creator></item></channel></rss>