[Full-Disclosure] openssl exploit code (e-secure-it owned)

From: Andrew Thomas (andrew@generator.co.za)
Date: 09/18/02


From: andrew@generator.co.za (Andrew Thomas)
Date: Wed, 18 Sep 2002 17:05:33 +0200

Hi,

A few comments I believe are in order.

Firstly, Erik has a point with regards to securing your own boxes. If
they're not secured tightly, why should a company trust information
proporting to come from you?

Secondly, I had a look at the business proposition that Arjen's group is now
following. I though it was a valuable service and I still believe it is a
valuable service.

Time=money, and perhaps you might be willing to take on an admin job that
requires +-8 hours a day, plus spend an additional 2-3 hours a day keeping
up with mailing lists in your own time, but not all are.

Or maybe you'd be willing to pay for another admin to work half-day to keep
up with the lists. Again, I wouldn't. I'd rather split the costs with
several other companies and keep my admin up to date with information
relevant to our internal architecture. I don't want to pay for my staff to
spend hours a day staying current with vulnerability information on
AIX/HPUX/Linux, when we're running a FreeBSD/Solaris shop.

Or what am I missing here?

Regards,
  Andrew



Relevant Pages

  • Re: PF Admin tool & Administrative Rights
    ... Best regards, ... Visit my website: http://www.infinitec.de ... > Actually I am testing with our lab server and the Ex admin path is ... > I tried to update the security descriptor for the same path but getting ...
    (microsoft.public.exchange2000.development)
  • Re: OT......unions
    ... Some have to meet quotas in regards to sex, ... so therefore the city has to pay to train ... needs the money the most. ... to do away with the pay a senior FF gets for longivity and pay the ...
    (rec.outdoors.rv-travel)
  • Re: Royal palaces "beyond repair" shocker
    ... :>> Due to the refusal of Betty Battenberg to cough up a measly few quid, ... :>> Regards, ... problem only arises when it is the taxpayer that is asked to pay. ...
    (alt.talk.royalty)
  • Re: M3 Die
    ... >justified this by saying "it would cost you more than that to get into ... I flatly refuse to pay to get into shows, I go to buy, OK I'll look ... PS Kevin, I'll have a look in the morning for a spare, must have one, ... Regards, ...
    (uk.rec.models.engineering)
  • Re: OPA349 spice model acting weird
    ... >>>Best regards, ... >model before I spend money for unknown quality. ... But I doubt anyone would pay. ...
    (sci.electronics.design)