Dailydave mailing list archives

Re: Fwd: [ISN] Security experts hit out at "unethical" bugfinder


From: H D Moore <hdm-daily-dave () digitaloffense net>
Date: Mon, 14 Mar 2005 13:02:44 -0600

Just to clarify, Digital Defense is not a VSC, they are a managed risk 
assessment service provider. While they do scan for and report a number 
of a non-public flaws, the vendors have been notified and either refused 
to address the problem or simply did not care. 

-HD

On Monday 14 March 2005 11:46, Chris Wysopal wrote:
Bug finders gain PR for their advisories that translates to real
business value: @stake, Foundstone, etc.  Still this is low value but
it does still effect vendor behavior.  Then there are higher value
vulnerability clubs, CERT, ISS, DigitalDefense.
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: