SlideShare a Scribd company logo
SETTING METHOD IN
CONSIDERATION OF THE PCI/DSS.
(PCI/DSS対応を考慮したVULS設定方
法)
@hogehuga
Today’s agenda
The subject of my LT is “Consider Vuls Settings with
the PCI/DSS”.
 We make clear what we do / do not it?
 do
 MUST
 MUST NOT
 RESTRICT
 about
 Vuls Server
 Target Server
 Service
Definition of term
 TargetServer
 To the test by using a Vuls.
 VulsServer
 The server to be inspected by Vuls
 vuls user
 User name “vuls” to use Vuls for inspection.
 Administrative user
 The user who can be connected to the “Vuls
server”.
Introduction
 To consider to the PCI/DSS, it is necessary to
take care of the following points.
 MUST NOT ASSIGN a special privilege to “vuls” user.
 Limited access, privileged, on a need-to-know basis.
 MUST REMOVE private key; About the “vuls” user of
TargetServer.
 Use SSH by Public key authentication when a VulsServer
access a TargetServer.
 MUST NOT Read/Write Vuls output data by general
user.
 Only privileged user can Read/Write Vuls output data.
 MUST RESTRICTED ACCESS and LOGGING to
Vuls output data.
 “Vuls output” include WEB( VulsRepo and the like)
POINT!
 Vuls server
 Login
 To restrict access to the Administrator.
 Logging the login.
 vuls user
 Limited privilege
 After setting the Vuls, sudo privileged is unnecessary.
 Logging the login/switch user to vuls.
 Vuls data (json reported data)
 To restrict access the Administrator/WEB process.
 Logging the access.
 WEB server
 Use Authentication access by Administrator.
 Logging the access.
POINT!
 Scanned Server
 vuls user
 Limited privilege by sudo.
 yum, apt-get only
 BSD does not require any sudo privilege
 Remove RSA private key
 Move(copy and delete) privatekey to VulsServer.
 Vuls Server only able to login to vuls.
Detail: Vuls server setting
For example…
 Prerequisite
 WEB server runs apache account.
 apache group contain vuls user.
 vuls user’s HOME is /opt/vuls .
 Login
 Only administrator can login the Vuls Server.
 Vuls data protection
 /opt/vuls/ is
 chmod 640 /opt/vuls
 chown vuls:apache /opt/vuls
 /opt/vuls/ssh_keys is
 chmod 600 /opt/vuls/ssh_keys
 chown vuls:vuls /opt/vuls/ssh_keys
 WEB Server
 Use /etc/hosts.allow, /etc/hosts.deny
 If basic authentication, MUST CHANGE every 90days and upper 7words(alphanumeric).
Detail: Scanned Server
For example
 Prerequisite
 vuls user’s HOME is /opt/vuls .
 Login
 MUST use key authentication.
 without passphrase , because using the Vuls as system.
 vuls user
 Limited setting to /etc/sudoers
 CentOS/RHEL
 vuls ALL=(root) NOPASSWD: /usr/bin/yum, /bin/echo
 Ubuntu, Debian
 vuls ALL=(root) NOPASSWD: /usr/bin/apt-get, /usr/bin/apt-cache
 Amazon LInux, FreeBSD
 Not required privilege settings.
 Remove the private key
 copy private key to Vuls Server, and remove private key on scanned server.
In conclusion
 I’m now going to give a brief summary of what we
have covered…
 Need-to-know basis
 limited privileged, restricted access, remove unnecessary
key.
 Logging, Logging, Logging!
Let’s patching software!
 PCI/DSS 6.2.a
 installation of applicable critical vendor-supplied
security patches within one month of release.
 Check security incident continuius by Vuls.
Sponser session.
 Thank you once again for talking the time to
join today’s presentation.
 we says, お疲れ様でした
 .. and sponsor session.

More Related Content

PDF
Future people v mware v sphere install configure manage v5.0 (1)
PPT
Virtualization s4.1
PDF
Vsphere 5.1 training at hyderabad
KEY
RocketJS Nodejs rapid development framework for production web apps
PDF
Vmware es xi 5.0 Training in Hyderabad
DOCX
Vmware training course
PPT
Presentation (PPT)
PPTX
Advantages of cPanel-based LiteSpeed Hosting
Future people v mware v sphere install configure manage v5.0 (1)
Virtualization s4.1
Vsphere 5.1 training at hyderabad
RocketJS Nodejs rapid development framework for production web apps
Vmware es xi 5.0 Training in Hyderabad
Vmware training course
Presentation (PPT)
Advantages of cPanel-based LiteSpeed Hosting

What's hot (20)

PPTX
Designing Azure compute and storage infrastructure
DOC
padmahasa november 2016 resume.Doc
DOCX
V mware course contents copy
DOCX
Vmware v sphere 5
PDF
Mastering VMware Datacenter Part-1
PDF
Introduction to MariaDb
PDF
Linux system administration - part-2
PDF
Mastering VMware Datacenter - 15 Modules
PDF
Introduction to Flow3
PDF
Drupal and Security: What You Need to Know
PPTX
Always on from the front lines1
PDF
Configuring CQ Security
PPT
How to configure esx to pass an audit
DOCX
Vm ware course content (1)
DOCX
What Is VMware
DOCX
Vmware Training Institute in chennai
DOC
Vmware interview
PDF
Protect Your WordPress Website - Setting Up IThemes Security
PDF
What Is VMware
DOC
Links todwnload
Designing Azure compute and storage infrastructure
padmahasa november 2016 resume.Doc
V mware course contents copy
Vmware v sphere 5
Mastering VMware Datacenter Part-1
Introduction to MariaDb
Linux system administration - part-2
Mastering VMware Datacenter - 15 Modules
Introduction to Flow3
Drupal and Security: What You Need to Know
Always on from the front lines1
Configuring CQ Security
How to configure esx to pass an audit
Vm ware course content (1)
What Is VMware
Vmware Training Institute in chennai
Vmware interview
Protect Your WordPress Website - Setting Up IThemes Security
What Is VMware
Links todwnload
Ad

Viewers also liked (20)

PDF
脆弱性情報はこうしてやってくる
PPTX
Vuls×deep security
PDF
Vulsで危険な脆弱性を最速検知!(The fastest detection of dangerous vulnerability by Vuls! )
PPTX
20170325 institute of-vulnerability_assessment
PPTX
Vulsで始めよう!DevSecOps!
PDF
東京オリンピックに向けた、サイバーテロ対策
PPT
Securing Your .NET Application
PDF
Maximizing your coaxial (cable tv) v2
PPT
Real Life Information Security
PDF
Łukasz Lenart "How secure your web framework is? Based on Apache Struts 2"
PDF
RootedCON 2015 - Deep inside the Java framework Apache Struts
PDF
バックアップの基礎知識
PPTX
Cyber Threat Hunting with Phirelight
PPTX
Go Hack Yourself - 10 Pen Test Tactics for Blue Teamers
PDF
.Net Hijacking to Defend PowerShell BSidesSF2017
PDF
Queue Size Trade Off with Modulation in 802.15.4 for Wireless Sensor Networks
PDF
hbstudy37 slide
PDF
●●●の知らないSBCの世界
PDF
マルウェア流入対策のもうひと工夫~プロが厳選!低予算でもできる効果あるセキュリティ施策~
PDF
Passive infrastructure of FTTH networks: an overview
脆弱性情報はこうしてやってくる
Vuls×deep security
Vulsで危険な脆弱性を最速検知!(The fastest detection of dangerous vulnerability by Vuls! )
20170325 institute of-vulnerability_assessment
Vulsで始めよう!DevSecOps!
東京オリンピックに向けた、サイバーテロ対策
Securing Your .NET Application
Maximizing your coaxial (cable tv) v2
Real Life Information Security
Łukasz Lenart "How secure your web framework is? Based on Apache Struts 2"
RootedCON 2015 - Deep inside the Java framework Apache Struts
バックアップの基礎知識
Cyber Threat Hunting with Phirelight
Go Hack Yourself - 10 Pen Test Tactics for Blue Teamers
.Net Hijacking to Defend PowerShell BSidesSF2017
Queue Size Trade Off with Modulation in 802.15.4 for Wireless Sensor Networks
hbstudy37 slide
●●●の知らないSBCの世界
マルウェア流入対策のもうひと工夫~プロが厳選!低予算でもできる効果あるセキュリティ施策~
Passive infrastructure of FTTH networks: an overview
Ad

Similar to SETTING METHOD IN CONSIDERATION OF THE PCI/DSS (20)

PDF
Hardening Apache Web Server by Aswin
PDF
Configuration of Self Signed SSL Certificate For CentOS 8
PDF
WordPress Security Best Practices 2019 Update
PPTX
Embrace and Extend - First-Class Activity and 3rd Party Ecosystem for SSIS in...
PPTX
Wordpress security issues
PPTX
Simple tips to improve Server Security
PPTX
Hands on workshop on word press
PPSX
Bo sa nova enterprise_pres_8
PPTX
Locking down word press
PDF
Null bhopal Sep 2016: What it Takes to Secure a Web Application
PPTX
AWS Cyber Security Best Practices
PDF
Top Ten WordPress Security Tips for 2012
PDF
WordPress Security
PDF
Cohesive networks Support Docs: VNS3:turret WAF Guide
PPTX
Introduction to the WSO2 Identity Server &Contributing to an OS Project
PPT
Securing Word Press Blog
PPTX
WordPress End-User Security
PDF
iSCSI Target Support for Ceph
PPTX
Cisco-Wireless-Guest-v10.pptx
PPTX
Log in to a Linux VM in Azure using AAD authentication
Hardening Apache Web Server by Aswin
Configuration of Self Signed SSL Certificate For CentOS 8
WordPress Security Best Practices 2019 Update
Embrace and Extend - First-Class Activity and 3rd Party Ecosystem for SSIS in...
Wordpress security issues
Simple tips to improve Server Security
Hands on workshop on word press
Bo sa nova enterprise_pres_8
Locking down word press
Null bhopal Sep 2016: What it Takes to Secure a Web Application
AWS Cyber Security Best Practices
Top Ten WordPress Security Tips for 2012
WordPress Security
Cohesive networks Support Docs: VNS3:turret WAF Guide
Introduction to the WSO2 Identity Server &Contributing to an OS Project
Securing Word Press Blog
WordPress End-User Security
iSCSI Target Support for Ceph
Cisco-Wireless-Guest-v10.pptx
Log in to a Linux VM in Azure using AAD authentication

More from hogehuga (20)

PDF
レトロゲーム勉強会:Diablo2の話Diablo II(オリジナル: 2000年-)は再び甦る
PPTX
LT大会資料 URL踏むとBSoDになる、心あたたまるお話
PPTX
水風呂道
PPTX
本当は怖いフリーWiFi(社内怪談LT)
PDF
最近のドローン界隈(仮)
PPTX
サウナととのいと水風呂ととのい
PPTX
Vuls祭り5 ; 脆弱性トリアージの考え方
PPTX
SIEMやログ監査で重要な事
PPTX
Owasp io t_top10_and_drone
PDF
Drone collection2019
PPTX
ハラスメントについて
PPTX
ハニーポットのログ、毎日アクセスログを見よう
PPTX
ドローンの現状とハッキング(概要版)
PPTX
Vuls祭りvol3
PDF
Honypotのログを見る
PDF
ハニーポッターと謎のアクセス
PPTX
WEBサイトのセキュリティ対策 -継続的なアップデート-
PPTX
20170408 securiy-planning
PPTX
Vuls ローカルスキャンモードの活用方法
PPTX
(Vulsで)脆弱性対策をもっと楽に!
レトロゲーム勉強会:Diablo2の話Diablo II(オリジナル: 2000年-)は再び甦る
LT大会資料 URL踏むとBSoDになる、心あたたまるお話
水風呂道
本当は怖いフリーWiFi(社内怪談LT)
最近のドローン界隈(仮)
サウナととのいと水風呂ととのい
Vuls祭り5 ; 脆弱性トリアージの考え方
SIEMやログ監査で重要な事
Owasp io t_top10_and_drone
Drone collection2019
ハラスメントについて
ハニーポットのログ、毎日アクセスログを見よう
ドローンの現状とハッキング(概要版)
Vuls祭りvol3
Honypotのログを見る
ハニーポッターと謎のアクセス
WEBサイトのセキュリティ対策 -継続的なアップデート-
20170408 securiy-planning
Vuls ローカルスキャンモードの活用方法
(Vulsで)脆弱性対策をもっと楽に!

Recently uploaded (20)

PPTX
Computer Software and OS of computer science of grade 11.pptx
PPTX
Transform Your Business with a Software ERP System
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PDF
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PPTX
assetexplorer- product-overview - presentation
PPTX
Embracing Complexity in Serverless! GOTO Serverless Bengaluru
PPTX
L1 - Introduction to python Backend.pptx
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PDF
medical staffing services at VALiNTRY
PPTX
Reimagine Home Health with the Power of Agentic AI​
PDF
Upgrade and Innovation Strategies for SAP ERP Customers
PPTX
history of c programming in notes for students .pptx
PDF
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
PDF
Design an Analysis of Algorithms II-SECS-1021-03
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PDF
Softaken Excel to vCard Converter Software.pdf
PDF
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
Computer Software and OS of computer science of grade 11.pptx
Transform Your Business with a Software ERP System
Wondershare Filmora 15 Crack With Activation Key [2025
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
wealthsignaloriginal-com-DS-text-... (1).pdf
assetexplorer- product-overview - presentation
Embracing Complexity in Serverless! GOTO Serverless Bengaluru
L1 - Introduction to python Backend.pptx
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
Odoo Companies in India – Driving Business Transformation.pdf
medical staffing services at VALiNTRY
Reimagine Home Health with the Power of Agentic AI​
Upgrade and Innovation Strategies for SAP ERP Customers
history of c programming in notes for students .pptx
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
Design an Analysis of Algorithms II-SECS-1021-03
Design an Analysis of Algorithms I-SECS-1021-03
Softaken Excel to vCard Converter Software.pdf
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf

SETTING METHOD IN CONSIDERATION OF THE PCI/DSS

  • 1. SETTING METHOD IN CONSIDERATION OF THE PCI/DSS. (PCI/DSS対応を考慮したVULS設定方 法) @hogehuga
  • 2. Today’s agenda The subject of my LT is “Consider Vuls Settings with the PCI/DSS”.  We make clear what we do / do not it?  do  MUST  MUST NOT  RESTRICT  about  Vuls Server  Target Server  Service
  • 3. Definition of term  TargetServer  To the test by using a Vuls.  VulsServer  The server to be inspected by Vuls  vuls user  User name “vuls” to use Vuls for inspection.  Administrative user  The user who can be connected to the “Vuls server”.
  • 4. Introduction  To consider to the PCI/DSS, it is necessary to take care of the following points.  MUST NOT ASSIGN a special privilege to “vuls” user.  Limited access, privileged, on a need-to-know basis.  MUST REMOVE private key; About the “vuls” user of TargetServer.  Use SSH by Public key authentication when a VulsServer access a TargetServer.  MUST NOT Read/Write Vuls output data by general user.  Only privileged user can Read/Write Vuls output data.  MUST RESTRICTED ACCESS and LOGGING to Vuls output data.  “Vuls output” include WEB( VulsRepo and the like)
  • 5. POINT!  Vuls server  Login  To restrict access to the Administrator.  Logging the login.  vuls user  Limited privilege  After setting the Vuls, sudo privileged is unnecessary.  Logging the login/switch user to vuls.  Vuls data (json reported data)  To restrict access the Administrator/WEB process.  Logging the access.  WEB server  Use Authentication access by Administrator.  Logging the access.
  • 6. POINT!  Scanned Server  vuls user  Limited privilege by sudo.  yum, apt-get only  BSD does not require any sudo privilege  Remove RSA private key  Move(copy and delete) privatekey to VulsServer.  Vuls Server only able to login to vuls.
  • 7. Detail: Vuls server setting For example…  Prerequisite  WEB server runs apache account.  apache group contain vuls user.  vuls user’s HOME is /opt/vuls .  Login  Only administrator can login the Vuls Server.  Vuls data protection  /opt/vuls/ is  chmod 640 /opt/vuls  chown vuls:apache /opt/vuls  /opt/vuls/ssh_keys is  chmod 600 /opt/vuls/ssh_keys  chown vuls:vuls /opt/vuls/ssh_keys  WEB Server  Use /etc/hosts.allow, /etc/hosts.deny  If basic authentication, MUST CHANGE every 90days and upper 7words(alphanumeric).
  • 8. Detail: Scanned Server For example  Prerequisite  vuls user’s HOME is /opt/vuls .  Login  MUST use key authentication.  without passphrase , because using the Vuls as system.  vuls user  Limited setting to /etc/sudoers  CentOS/RHEL  vuls ALL=(root) NOPASSWD: /usr/bin/yum, /bin/echo  Ubuntu, Debian  vuls ALL=(root) NOPASSWD: /usr/bin/apt-get, /usr/bin/apt-cache  Amazon LInux, FreeBSD  Not required privilege settings.  Remove the private key  copy private key to Vuls Server, and remove private key on scanned server.
  • 9. In conclusion  I’m now going to give a brief summary of what we have covered…  Need-to-know basis  limited privileged, restricted access, remove unnecessary key.  Logging, Logging, Logging! Let’s patching software!  PCI/DSS 6.2.a  installation of applicable critical vendor-supplied security patches within one month of release.  Check security incident continuius by Vuls.
  • 10. Sponser session.  Thank you once again for talking the time to join today’s presentation.  we says, お疲れ様でした  .. and sponsor session.