whoisjb
03-26-2007, 08:57 AM
We have a client that runs a vulnerability scan on their site every quarter. Since we've just recently moved their site to our new Interworx box, they found some new vulnerabilities they'd like us to address.
1. SSL 2.0 - They'd like us to disable this but I'm not sure how or why it's a security issue. Any ideas how to do this?
2. Microsoft IIS SSL - This one really confuses me since we're running CentOS. I'm not sure how they could detect an IIS vulnerability on a Linux box. Specifically it's the MS04-011 vulnerability. Any clue how this could even get triggered?
3. DNS server - They say our DNS server doesn't respond to TCP requests but only UDP. Is this the normal configuration for Interworx?
1. SSL 2.0 - They'd like us to disable this but I'm not sure how or why it's a security issue. Any ideas how to do this?
2. Microsoft IIS SSL - This one really confuses me since we're running CentOS. I'm not sure how they could detect an IIS vulnerability on a Linux box. Specifically it's the MS04-011 vulnerability. Any clue how this could even get triggered?
3. DNS server - They say our DNS server doesn't respond to TCP requests but only UDP. Is this the normal configuration for Interworx?