[Full-Disclosure] [Full Disclosure] *HACKERS COSTING ENTERPRISES BILLIONS

From: RandallM (randallm_at_fidmail.com)
Date: 09/20/04

  • Next message: bipin gautam: "[Full-Disclosure] JPG worm!"
    To: <full-disclosure@lists.netsys.com>
    Date: Mon, 20 Sep 2004 06:07:16 -0500
    
    

     

    A report issued by Symantec found that:

    "The average time period between the disclosure of a vulnerability and its
    first exploit by hackers collapsed from several weeks in past reports to
    less than six days in the first half of 2004.

    'In some cases, we saw global exploits in less than two days,' said Weafer.
    The current report finds that the vast majority of those vulnerabilities
    were moderately to highly severe and nearly 40% were associated with Web
    applications."

    This and some other findings from it's "Internet Security Threat Report."
    See
    Security Wire Perspectives, Vol. 6, No. 72, September 20, 2004 for this and
    other related
    Material.
     
    thank you
    Randall M
     

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: bipin gautam: "[Full-Disclosure] JPG worm!"

    Relevant Pages

    • RE: Question About Ethics and Full Disclosure
      ... vulnerability, you should try and report the fix for it too. ... >Below is an outline for my disclosure process. ... >BTW...I have sent several emails to various parts of VeriSign and NOBODY ...
      (Bugtraq)
    • Minimizing error cascades in vulnerability information management
      ... throughout vulnerability disclosure, ... important discrepancies, ... spelling discrepancy in the original ProCheckUp report triggered some ... affected versions, disclosure dates, and researcher credits. ...
      (Bugtraq)
    • Re: Starting a Pen-Testing Career
      ... Perhaps my perceptions of the business are a bit naive, ... Buinsesses don't care about security and vulnerabilty and exposure. ... How else would they be able to provide such a report in isolation - ... written vulnerability scanner' to produce reports. ...
      (alt.computer.security)
    • RE: MBSA scanner
      ... the license must state clearly what is restricted. ... that referred to the nature of the vulnerability or exploit itself would be ... > all the suggestions on how to fix a vulnerability that a report might ... > nothing preventing Nessus, Internet Scanner, Cybercop, Retina, ...
      (Pen-Test)
    • Re: MBSA scanner
      ... all the suggestions on how to fix a vulnerability that a report might ... > Nessus is another example; the GPL has the same restrictions on distribution ... And also read the GPL FAQ: ...
      (Pen-Test)

  • Quantcast