Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Nameservers getting unrelevant findings (e.g. about e-mailsecurity) #1308

Open
zcrt opened this issue Jul 3, 2023 · 2 comments
Open

Nameservers getting unrelevant findings (e.g. about e-mailsecurity) #1308

zcrt opened this issue Jul 3, 2023 · 2 comments
Assignees
Labels
bug Something isn't working

Comments

@zcrt
Copy link
Contributor

zcrt commented Jul 3, 2023

Describe the bug
Currently, when scanning a hostname it can be the case that a corresponding name server is found. For this name server findings can be generated about e-mail security, while that is not necessarily relevant to the scanned hostname.

To Reproduce
Steps to reproduce the behavior:

  1. Scan a hostname with L3 and an ns without SPF
  2. Notice SPF findings

Expected behavior
It would be nice if it can be configured what kind of findings should be generated for nameservers. Or maybe a toggle 'generate e-mail findings on nameservers'. It may be the case that this holds for other findings next to e-mail and other objects next to nameservers.

OpenKAT version
1.8

@zcrt zcrt added the bug Something isn't working label Jul 3, 2023
@underdarknl
Copy link
Contributor

Maybe we should see what services are running on a machine and then decide on what specifics are reasonable. Eg, is we know some host is a Mailhost (because we see mail ports/services) we want to see other security measures as opposed to a machine doing nameserver services or http services.

@zcrt zcrt moved this to Pilot in OpenKAT @ Z-CERT Aug 17, 2023
@dekkers
Copy link
Contributor

dekkers commented Sep 21, 2023

First step towards solving this is knowing what the context of a host is, we are working on that in #1657.

@TwistMeister TwistMeister added this to KAT Sep 28, 2023
@github-project-automation github-project-automation bot moved this to Incoming features / Need assessment in KAT Sep 28, 2023
@TwistMeister TwistMeister moved this from Incoming features / Need assessment to Approved features / Need refinement in KAT Sep 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
Status: Approved features / Need refinement
Development

No branches or pull requests

3 participants