NOC REPORTING TEMPLATE – Client attorney work product
Date Updated: Name: Robert Pimentel
A. Introduction - – Client attorney work product
As the Incident Response Manager (IR) in
Psinuvia Inc’s new NOC, we are runni
...
NOC REPORTING TEMPLATE – Client attorney work product
Date Updated: Name: Robert Pimentel
A. Introduction - – Client attorney work product
As the Incident Response Manager (IR) in
Psinuvia Inc’s new NOC, we are running a
vulnerability assessment as well as regularly
planned scanning on all the organization’s
systems.
In order to determine the existence of
vulnerabilities on our system, we will perform a
vulnerability scan and report on any
vulnerabilities or intrusions detected.
B. Vulnerability Scan– Client attorney work product
(Attach as Appendix A)
C. Scan Summary– Client attorney work product
2 systems were found vulnerable:
172.20.1.129
172.20.1.131
3 serious vulnerabilities were discovered in 172.20.1.131
31 high severity vulnerabilities were discovered in 172.20.1.131
15 informational severity alerts were issued for 172.20.1.129
Top 10 Attacker Host report shows 3 systems as threat actors in this environment:
10.232.33.32 on 16863 instances
AlienVault on 1054 instances
10.163.159.91 on 6 instances
172.20.1.1 on 6 instances
This study source was downloaded by 100000831988016 from CourseHero.com on 08-08-2022 10:04:52 GMT -05:00
https://www.coursehero.com/file/61243818/NOC-Reporting-Templatedocx/
Top 10 Attacked Hosts show the 2 systems that were deemed vulnerable during the vulnerability
scan as victims:
172.20.1.131 on 17808 instances
172.20.1.129 on 194 instances
Top 15 Alarms show 5 attacks performed repeatedly on these targets:
AlienVault HIDS: SQL injection attempt. on 15860 instances
AlienVault HIDS: Multiple SQL injection attempts from same source ip. on 2273 instances
Delivery & Attack — WebServer Attack SQL Injection — Attack Pattern Detection on 6
instances
Exploitation & Installation — Webserver Attack — XSS on 2 instances
Delivery & Attack — Brute force Authentication — SSH on 2 instances
D. Detailed Analysis– Client attorney work product
3 serious vulnerabilities were discovered in 172.20.1.131 in the following services:
SSH, HTTP, traceroute
31 high severity vulnerabilities were discovered in 172.20.1.131 in the following services:
1. OpenSSL - End of life detection
2. Untrusted SSL/TLS Certificate Authorities
3. PHP - End of life detection
4. HTTP/HTTPS -
1. Apache HTTP Server 2.4.37 mod_ssl DoS Vulnerability (Windows)
2. Apache HTTP Server < 2.4.39 mod_ssl Access Control Bypass Vulnerability
(Windows)
3. Apache HTTP Server < 2.4.39 URL Normalization Vulnerability (Windows)
4. Apache HTTP Server < 2.4.38 HTTP/2 DoS Vulnerability (Windows)
5. Apache HTTP Server < 2.4.38 mod_session_cookie Vulnerability (Windows)
6. PHP 'PHP-FPM' Denial of Service Vulnerability (Windows)
7. PHP Integer Overflow Vulnerability Aug18 (Windows)
This study source was downloaded by 100000831988016 from CourseHero.com on 08-08-2022 10:04:52 GMT -05:00
https://www.coursehero.com/file/61243818/NOC-Reporting-Templatedocx/
8. Apache HTTP Server < 2.4.39 mod_auth_digest Access Control Bypass
Vulnerability (Windows)
9. PHP Integer Overflow Vulnerability Aug18 (Windows)
10. PHP Memory Disclosure Vulnerability (Windows)
11. PHP Multiple Vulnerabilities - Feb19 (Windows)
12. phpinfo() output accessible
13. Apache HTTP Server < 2.4.39 mod_http2 DoS Vulnerability (Windows)
b. SMTP -
1. Check if Mailserver answer to VRFY and EXPN requests
2.
8 medium severity vulnerabilities were discovered in 172.20.1.131 in the following services:
1. HTTP/HTTPS
1. Apache HTTP Server < 2.4.39 mod_http2 DoS Vulnerability (Windows)
b. FTP
1. FTP Unencrypted Cleartext Login
b. IMAP
1. IMAP Unencrypted Cleartext Logins
b. OpenSSL
1. OpenSSL: 0-byte record padding oracle (CVE-2019-1559) (Windows)
b. DSA Signature generation
1. Timing vulnerability in DSA signature generation (CVE-2018-0734) (Windows)
b. POP3
1. POP3 Unencrypted Cleartext Logins
b. SSL/TLS
1. SSL/TLS: Certificate Signed Using A Weak Signature Algorithm
1 low severity vulnerability was discovered in 172.20.1.131
1. SSL/TLS
1. OpenSSL: Microarchitecture timing vulnerability in ECC scalar multiplication (CVE2018-5407) (Windows)
52 informational severity alerts were issued for 172.20.1.131
1. SSL/TLS
1. SSL/TLS: HTTP Strict Transport Security (HSTS) Missing
1. SSL/TLS: NPN / ALPN Extension and Protocol Support Detection
2. OpenSSL Remote Version Detection
3. SSL/TLS: Certificate - Self-Signed Certificate Detection
4. SSL/TLS: Collect and Report Certificate Details
5. SSL/TLS: HTTP Public Key Pinning (HPKP) Missing
2. POP3
1. Unknown OS and Service Banner Reporting
This study source was downloaded by 100000831988016 from CourseHero.com on 08-08-2022 10:04:52 GMT -05:00
https://www.coursehero.com/file/61243818/NOC-Reporting-Templatedocx/
2. POP3 Missing Support For STLS
3. POP3 Server type and version
3. SSH
1. Unknown OS and Service Banner Reporting
4. XAMPP
1. XAMPP Version Detection
5. HTTP/HTTPS
1. Apache Web Server Version Detection
2. CGI Scanning Consolidation
3. HTTP Security Headers Detection
4. HTTP Server type and version
5. PHP Version Detection (Remote)
6. CPE
1. CPE Inventory
7. FTP
1. FileZilla Server Version Detection
2. FTP Banner Detection
3. FTP Missing Support For AUTH TLS
8. IMAP
1. IMAP Missing Support For STARTTLS
2. IMAP Banner
3. jQuery Detection
4. LDAP Detection
5. MySQL/MariaDB Detection
6. Nikto (NASL wrapper)
9. OS Detection Consolidation and Repo
[Show More]