Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Correction to latest Colsaire advisories |
|---|---|
| Date: | Thu, 16 Sep 2004 11:29:56 +0100 |
I presume that these are nine of the "top 10 content providers".
Actually, no. Our internal testing covered a limited collection of what we considered the most prevalent enterprise products. When it became clear that the issues were widespread, we brought NISCC in to coordinate passing out a set of canned test tools to all the MIME related vendors they could find (anecdotally, I think this was something like 100+). We obviously have the results of our own testing (which is where the stats come from), but the other vendors have been invited to make their own declaration as to the outcome of the test tools. Needless to say the statements provided so far are somewhat sparse; the only vendor from our original test set to make a statement is F-Secure.
I also note that Microsoft was not listed as a vendor that responded. Were their products tested and if so what were the results?
Yes, they were tested. Yes, they have chosen not to make a public statement. I personally don't know why this may be so. Perhaps you could ask them? ;) The release model for these vulnerabilities has been the best compromise of what is a difficult situation. Releasing as individual advisories (or per-product clumps) was never going to be ideal; both because of the volume and because earlier public releases expose information about products that come later in the process. The solution chosen was to pick a date far-off in the future, to provide the vendors with all the information they needed to replicate the issues, and then to allow them to make their own public statements as to compliance. Effectively the same model as the SNMP issues from a few years ago. History may prove this not to be ideal, and a better model may be needed. Regards, Martin O'Neal
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Microsoft GDIPlus.DLL JPEG Parsing Engine Buffer Overflow, Angelidis, Fotis(NSASOUDABAY) |
|---|---|
| Next by Date: | www.proboards.com / YaBB XSS Vuln, admin |
| Previous by Thread: | TSLSA-2004-0047 - multi, Trustix Security Advisor |
| Next by Thread: | RE: Correction to latest Colsaire advisories, David Litchfield |
| Indexes: | [Date] [Thread] [Top] [All Lists] |