Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Review website status after July 18/19 Tenable scan #3833

Closed
jason-upchurch opened this issue Jun 21, 2019 · 4 comments
Closed

Review website status after July 18/19 Tenable scan #3833

jason-upchurch opened this issue Jun 21, 2019 · 4 comments
Assignees
Labels
Security: general General security concern or issue
Milestone

Comments

@jason-upchurch
Copy link
Contributor

jason-upchurch commented Jun 21, 2019

Problem

Tenable scans from the evenings of April 18/19 and May 18/19 were correlated with temporary website outages.

The scan from the evening of June 18/19 crashed and did not complete. There was no website outage during that scan.

We need to follow up after the July 18/19 scan to determine if the scan is again correlated with an outage. Log time of scans and duration.

Related issue: fecgov/fec-cms#2910

@jason-upchurch
Copy link
Contributor Author

emailed Michael to determine if scan completed as expected. New Relic alerts corresponding to scan timeframe (but not necessarily the Tenable IP):

(most recent at top)

Incident 76477192
Incident 76477181
Incident 76477150
Incident 76477033
Incident 76476903
Incident 76476403
Incident 76476336
Incident 76476324
Incident 76476321
Incident 76476295
Incident 76476235
Incident 76476224
Incident 76476164
Incident 76476026
Incident 76476017
Incident 76475924

Also included details on issue fecgov/fec-cms#2989

@jason-upchurch
Copy link
Contributor Author

Michael advised scan completed as expected.

@jason-upchurch
Copy link
Contributor Author

next step: see if any incidents correspond to the Tenable scan IP address.

@jason-upchurch
Copy link
Contributor Author

Added incident IDs to issue fecgov/fec-cms#2989. Closing this issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Security: general General security concern or issue
Projects
None yet
Development

No branches or pull requests

2 participants