Re: Scanners and unpublished vulnerabilities - Full Disclosure

From: Brad Mills (millsmiami@usa.net)
Date: 05/29/02


Date: Wed, 29 May 2002 12:33:02 EDT
To: Vanja Hrustic <vanja@vanja.com>, pen-test@securityfocus.com
From: Brad Mills <millsmiami@usa.net>


> It won't make any difference whatsoever. It's time to realize that 'we'
> don't make any difference.
>
> Vendors still don't react to problems, silly bugs are still present in
> software, admins still don't patch/upgrade, users still click on
> attachments and download screen savers.

 Hmmm, unless I missed something, it was lists like this that generated
the recent Best-Buy wireless energy, which resulted in sub-actions,
eventually causing the company to stop and re-evaluate things.
 
 As for sh*t software, vendors, typical end-users, etc., it will take
time, but if the catalyst weakens now, energy expended is lost. I say
continue the march.
 
 just my .02,
 /b

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: Scanners and unpublished vulnerabilities - Full Disclosure
    ... It won't make any difference whatsoever. ... Vendors still don't react to problems, silly bugs are still present in ... Management still wants security audits so that they can blame the security ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • The sky is falling, or so I am told.
    ... vendors proclaiming our impending doom. ... all of the notifications everyone did on the first round plus the ... Should you like to submit offending hosts for ... This list is provided by the SecurityFocus ARIS analyzer service. ...
    (Incidents)
  • Re: Scanners and unpublished vulnerabilities - Full Disclosure
    ... > often the very latest vulnerabilities come into play in their work. ... SecurityFocus was working on for CORE ST to report to a series of vendors ... > holes Microsoft fixed. ...
    (Pen-Test)