Re: Scanners and unpublished vulnerabilities - Full Disclosure

From: Renaud Deraison (deraison@nessus.org)
Date: 05/29/02


Date: Wed, 29 May 2002 01:16:06 +0200
From: Renaud Deraison <deraison@nessus.org>
To: pen-test@securityfocus.com

On Tue, May 28, 2002 at 12:05:43PM -0600, Alfred Huger wrote:
> In brief they are now unloading limited details to the public about
> vulnerabilities they have notified vendors about.

I'm not surprised - three years ago, I said that would happen[1],
although I was expecting tighter cooperation between producers of
security holes (software vendors) and scanners.

When antivirus publishers have been accused of _secretely_ funding the
developement of new virii, they have been slammed by everyone. Oddly,
scanning for unknown vulnerabilities seems to be something worth to brag
about.
                                -- Renaud

[1] http://security-archive.merton.ox.ac.uk/bugtraq-199907/0014.html

-- 
Renaud Deraison
The Nessus Project
http://www.nessus.org

---------------------------------------------------------------------------- This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/



Relevant Pages

  • RE: Scanners and unpublished vulnerabilities - Full Disclosure
    ... http://eEye.com/Retina - Network Security Scanner ... | Subject: RE: Scanners and unpublished vulnerabilities - Full Disclosure ... I don't only want protection from 0 day exploits, ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • RE: Scanners and unpublished vulnerabilities - Full Disclosure
    ... vulnerabilities that other products wont be able to. ... http://eEye.com/Retina - Network Security Scanner ... |> Alert Scheme the folks over at NGSSoftware announced yesterday. ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: PeopleSoft Vulnerabilities?
    ... Subject: PeopleSoft Vulnerabilities? ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: ethics of approaching vulnerable prospective clients
    ... I routinely notify vulnerable networks and send reports that have full ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... automatically alerts you to the latest security vulnerabilities please see: ...
    (Pen-Test)
  • Re: XSS LAB DEMO IDEAS
    ... It uses an iPlanet XSS vulnerability as a case study. ... Next Generation Security Technologies ... For more information on SecurityFocus' SIA service which ... automatically alerts you to the latest security vulnerabilities please see: ...
    (Pen-Test)