Re: MBSA scanner

From: Javier Fernandez-Sanguino (jfernandez_at_germinus.com)
Date: 05/10/04

  • Next message: Timothy Marshall: "RFID Tags"
    Date: Mon, 10 May 2004 09:04:12 +0200
    To: Steven Trewick <STrewick@joplings.co.uk>
    
    

    Steven Trewick wrote:
    >
    >>>I think you're confusing code with output. The licenses
    >>>you cite with regard to both SARA and MBSA have restrictions upon
    >>>redistribution of the product, not the output of the product.
    >
    >
    >>I'm confusing them because output might _include_ significant
    >>information that is in the code. The license covers both the software
    >>and the reports they generate, it does not explicitly exclude the
    >>later (so under copyright laws it _is_ included).
    >
    > To start with :
    >
    >
    > To which copyright law, and in which country are you referring, exactly ?

    That would be the WIPO copyright treaty [1] (regarding copyright law)
    and the GPL _license_ [2] regarding SARA and Nessus use of copyright
    law. Obviously, different countries have different (more detailed)
    copyright laws, but most (all?) uphold to that treaty including
    redistribution and public communication. The data (i.e. vulnerability
    information wether separate or included in the code) in any of these
    tools is a database on its own right, this data is introduced into the
    output of the program (i.e. the reports). Moreover, this data is a
    sustantiable part of the report.

    As far as I see, a report of a vulnerability assessment tool without
    detailed information of the discovered vulnerability, impact,
    remediation, and links to external sources is not really useful. It
    would be not more than lines saying "found vulnerability XYZ in system
    0 in port A" which, even if it useful for an auditor, leaves him an
    enormous amount of work related to: digging vulnerability impact, risk
    involved, more details in order to weed out false positives....

    Regards

    Javier

    [1] http://www.wipo.int/documents/en/diplconf/distrib/94dc.htm
    [2] http://www.fsf.org/licenses/licenses.html#TOCGPL

    ------------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    -------------------------------------------------------------------------------


  • Next message: Timothy Marshall: "RFID Tags"

    Relevant Pages

    • Re: [Full-disclosure] Vulnerabilities digest
      ... Elektreports protection bypass vulnerability in ... Original message (in Russian): ...
      (Full-Disclosure)
    • [Full-disclosure] Vulnerabilities digest
      ... Original message (in Russian): http://securityvulns.ru/Sdocument67.html ... MustLive reports Crossite-Cripting vulnerability in WordPress ... Original message: http://securityvulns.ru/Rdocument875.html ...
      (Full-Disclosure)
    • Vulnerabilities digest
      ... Original message (in Russian): http://securityvulns.ru/Sdocument67.html ... MustLive reports Crossite-Cripting vulnerability in WordPress ... Original message: http://securityvulns.ru/Rdocument875.html ...
      (Bugtraq)
    • Manage Engine Exchange Reporter v4.1 - Multiple Web Vulnerabilites
      ... Manage Engine Exchange Reporter v4.1 - Multiple Web Vulnerabilites ... Microsoft Exchange Server is, by a distance, the most popular communication, collaboration and email messaging application today! ... The range includes reports of crucial importance. ... The Vulnerability Laboratory Research Team discovered multiple web vulnerabilities in Exchange Reporter v4.1 Plus. ...
      (Bugtraq)
    • [Full-disclosure] Fwd: IE7 is a Source of Problem - Secunia IE7 Release Incident of October
      ... IE7 is a Source of Problem - Secunia IE7 Release Incident ... I am not defending Microsoft. ... and Microsoft say "These reports are technically inaccurate: ... if you have to write down a vulnerability report on it?. ...
      (Full-Disclosure)