Re: Scanners and unpublished vulnerabilities - Full Disclosure

From: Renaud Deraison (deraisonat_private)
Date: Tue May 28 2002 - 16:16:06 PDT

  • Next message: Marc Maiffret: "RE: Scanners and unpublished vulnerabilities - Full Disclosure"

    On Tue, May 28, 2002 at 12:05:43PM -0600, Alfred Huger wrote:
    > In brief they are now unloading limited details to the public about
    > vulnerabilities they have notified vendors about.
    
    I'm not surprised - three years ago, I said that would happen[1],
    although I was expecting tighter cooperation between producers of
    security holes (software vendors) and scanners. 
    
    When antivirus publishers have been accused of _secretely_ funding the
    developement of new virii, they have been slammed by everyone. Oddly, 
    scanning for unknown vulnerabilities seems to be something worth to brag
    about.
    				-- Renaud
    
    [1] http://security-archive.merton.ox.ac.uk/bugtraq-199907/0014.html
    
    -- 
    Renaud Deraison
    The Nessus Project
    http://www.nessus.org
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/
    



    This archive was generated by hypermail 2b30 : Tue May 28 2002 - 16:25:33 PDT