Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: Re: [WEB SECURITY] Re: Oracle in war of words with security researcher

Re: [WEB SECURITY] Re: Oracle in war of words with security researcher

From: Valkyrie <valkyrie_at_hacktek.com>
Date: Fri, 27 Jan 2006 15:59:15 -0800

Is this truly a case of Oracle's people being terrible to deal with when
it comes to security research and response, or is it more toward the
corporate culture that may influence how quickly the organization
responds to issues? I could contend the same thing for several
enterprise software and security software/hardware vendors presently in
the IT space. A culture of trusted advisory and responsiveness to end
users just doesn't *seem* to be on the "Top 5 Initiatives" list. Again,
my assertion goes back to failure to have received a logical response to
the question, "How long is too long to fix your stuff?" Martin has
highlighted some excellent points from what may be a vendor perspective,
however, those points do not necessarily help resolve this issue.

Regards,
valkyrie

Byron Sonne wrote:

>> This isn't picking on Oracle, this is true for all vulnerabilities in
>> widely used publicly available products.
>
>
> Oracle *should* be picked on though: they're terrible people to deal
> with when it comes to security research.
>
> ---------------------------------------------------------------------
> The Web Security Mailing List
> http://www.webappsec.org/lists/websecurity/
>
> The Web Security Mailing List Archives
> http://www.webappsec.org/lists/websecurity/archive/
>

-------------------------------------------------------------------------
This List Sponsored by: Watchfire

Watchfire's AppScan is the industry's first and leading web application
security testing suite, and the only solution to provide comprehensive
remediation tasks at every level of the application. See for yourself.
Download AppScan 6.0 today.

https://www.watchfire.com/securearea/appscansix.aspx?id=701300000003Ssh
--------------------------------------------------------------------------
Received on Jan 27 2006

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]