Re: Scanners and unpublished vulnerabilities - Full Disclosure

From: David Litchfield (mnemonix@globalnet.co.uk)
Date: 05/29/02


From: "David Litchfield" <mnemonix@globalnet.co.uk>
To: <pen-test@securityfocus.com>
Date: Wed, 29 May 2002 00:07:35 +0100

Many people in this industry know me, if not personally, then by reputation
and know I have always been a supporter of full disclosure. The idea behind
the VNA is exactly as we state on the web site. It exists as a method to
"persuade" vendors to provide their customers with a patch rather than
silently supply security fixes in a service pack. We all know that trying to
keep up with patches can be a never ending task - however - if there is a
security problem in the software I use I'd rather be able assess the risk to
me or my organization myself and determine if I need to install the patch or
whether I can wait until the next service pack comes out. In the absence of
a patch I can't make this choice though - the vendor has done the risk
assessment for me - and this is useless - how can they, not knowing my
circumstances, decide for me whether a security problem should be left for
the next 8 months until the next service pack is due out?

I'd rather see vendors furnishing their customers with the right information
and a patch so the _customer_ can decide whether the want or need to fix the
hole.

Now - what has been happening recently is quite the opposite. Vendors have
been moving away from providing a patch to rolling them up in service packs.
Hence the VNA. I feel that once a vendor is publicly seen to have a problem
with their code then the only responsible thing they can do it provide their
customers with a patch.

The VNA is not some marketing scheme. Whenever I have discovered a problem
it has always (well 90% of the time) immediately gone into Cerberus Internet
Scanner or Typhon so this aspect of the VNA thing is not new by any stretch
of the imagination. What's more the VNAs are not posted to any mailing
list - only posted on our site. Those who most come to our site are our
customers - and I don't need to market to these people.

I hope this clears up some of the speculation.

Cheers,

David Litchfield

http://www.ngssoftware.com/

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • [security bulletin] HPSBST02379 SSRT080143 rev.1 - Storage Management Appliance (SMA), Microsoft
    ... The information in this Security Bulletin should be acted upon as soon as possible. ... The SMA must have all pertinent SMA Service Packs applied ... Patch installation instructions are shown at the end of this table. ... Action - Customers should not be concerned with this issue ...
    (Bugtraq)
  • [security bulletin] HPSBST02360 SSRT080117 rev.2 - Storage Management Appliance (SMA), Microsoft
    ... The information in this Security Bulletin should be acted upon as soon as possible. ... The SMA must have all pertinent SMA Service Packs applied ... MS Patch - MS08-041 Vulnerability in the ActiveX Control for the Snapshot Viewer for Microsoft Access ... Action - Customers should not be concerned with this issue ...
    (Bugtraq)
  • Re: Q329170 (MS02-070), Q327984 and slow logoffs
    ... Service Pack 4", the problem described by Chris Hill on 3/21/03 ... > security bulletin, your computer takes a long time to log off (up to ... > by a handle leak in shlwapi32.dll' whereas this patch does not exist ... Summer's Hottest Certification Just Got HOTTER! ...
    (NT-Bugtraq)
  • Re: Cryptogram Comment
    ... >> customers and shareholders. ... so I'll go steal a Ford F150 truck now. ... >> serious mistake in its decision not to make the upcoming patch freely ... >> security and provides exactly the sort of evidence that its detractors ...
    (sci.crypt)
  • [security bulletin] HPSBST02194 SSRT071306 rev.1 - Storage Management Appliance (SMA), Microsoft
    ... The information in this Security Bulletin should be acted upon as soon as possible. ... The SMA must have all pertinent SMA Service Packs applied. ... Patch installation instructions are shown at the end of this table. ... customers should download patch from Microsoft and install. ...
    (Bugtraq)