Qualys mis-uses ssh, fails to scan and protect, facilitates internal attack

Read Time:18 Second

Posted by Paul Szabo via Fulldisclosure on Aug 11

=== Introduction ===================================================

My institution uses Qualys

www.qualys.com

to scan for vulnerabilities, including on some Debian Linux machines
that I manage. The scanner does some network scans, and also logs in
to each machine to do “authenticated scans”.

=== Discovery ======================================================

When I recently updated my machines from Debian11 to Debian12, the…

Read More