Some time ago, I was digging into CVE and I wondered if we shouldn't test very old vulnerabilities (because we do not. Not *all* of them) Two reasons for yes: 1. An archeocomputer may have been lost in a corner of a network. 2. People never learn, and old bugs tend to pop up sooner or later One reason for no: why bother? We have enough new vulnerabilities now. Yes? No?
This archive was generated by hypermail 2b30 : Mon Mar 03 2003 - 15:57:30 PST