Re: [Full-Disclosure] Vulnerability response times -- MS and others

From: Tim (tim-security_at_sentinelchicken.org)
Date: 04/07/04

  • Next message: madsaxon: "Re: [Full-Disclosure] Wiretap or Magic Lantern?"
    To: full-disclosure@lists.netsys.com
    Date: Wed, 7 Apr 2004 12:42:47 -0700
    
    

    > Now... what about the following? I cannot read the Forrester report --
    > I am not a client, and I do not wish to spend $899 on it... so I
    > cannot discuss the metrics used, nor how Forrester determined what was
    > a "vulnerability disclosure".
    >
    > Given the fact that a lot of the MS security fixes were privately
    > disclosed to MS (and public announcement was withheld until MS put out
    > a fix), this *may* have played a role.
    >
    > Anyways... the report seems to indicate that Microsoft is the fastest
    > on solving security issues.
    >
    > Comments?

    There is a huge mis-conception among some in the security community that
    "public announcement" means a whole lot. When it comes to protecting
    your network from malicious individuals (not the 4th rate viruses we are
    currently seeing), the most important event is when the vulnerability
    was first discovered. That is also the hardest date to pin down, but it
    is critical that from the time the vulnerability was discovered (not
    publicly disclosed) to the time a patch is released is small. Microsoft
    lags tremendously on this
    (see http://www.eeye.com/html/Research/Upcoming/index.html for examples).

    Any research that doesn't at least attempt to estimate the discovery
    date is not worth the paper it is printed on, imho. Of course I haven't
    read this report, but that's my take on the topic generally.

    tim

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: madsaxon: "Re: [Full-Disclosure] Wiretap or Magic Lantern?"

    Relevant Pages

    • SecurityFocus Microsoft Newsletter #176
      ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows XP HCP URI Handler Arbitrary Command Execu... ... PHPNuke Category Parameter SQL Injection Vulnerability ... Microsoft Baseline Security Analyzer Vulnerability Identific... ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #242
      ... MICROSOFT VULNERABILITY SUMMARY ... PostNuke Blocks Module Directory Traversal Vulnerability ... Groove Networks Groove Virtual Office COM Object Security By... ... The Microsoft Windows IPV6 TCP/IP stack is prone to a "loopback" condition initiated by sending a TCP packet with the "SYN" flag set and the source address and port spoofed to equal the destination source and port. ...
      (Focus-Microsoft)
    • [NT] Cumulative Security Update for Internet Explorer (MS04-025)
      ... Get your security news from a reliable source. ... * Microsoft Windows NT Workstation 4.0 Service Pack 6a ... Navigation Method Cross-Domain Vulnerability ...
      (Securiteam)
    • SecurityFocus Microsoft Newsletter # 87
      ... Meeting IT Security Benchmarks Through IT Audits ... MICROSOFT VULNERABILITY SUMMARY ... Bypassing Windows 2000 Domain Password settings ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #75
      ... Microsoft's Internet Security & Acceleration Server with fault-tolerance ... The Microsoft UPnP Vulnerability ... Relevant URL: ...
      (Focus-Microsoft)

  • Quantcast