Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Information-Security-News
[Top] [All Lists]

[ISN] Qualys vulnerability research put in peril

Subject: [ISN] Qualys vulnerability research put in peril
Date: Wed, 11 Jan 2006 00:49:26 -0600 (CST)
http://www.techworld.com/security/news/index.cfm?NewsID=5128

By John E. Dunn
Techworld
10 January 2006

Security management vendor Qualys has denied that its innovative Laws
of Vulnerability research has been jeopardised by the sudden departure
of its key instigator, Gerhard Eschelbeck.

The company has confirmed that no individual had been appointed to
directly replicate Eschelbeck's work on the research, an analysis of
real-world vulnerabilities taken from scans of Qualys's substantial
enterprise customer base. The findings for 2005 were announced last
November at the Black Hat conference in Las Vegas.

Former company CTO and VP of engineering, Eschelbeck, announced before
Christmas that he was leaving the company he'd worked at for five
years to take up an identical position at anti-spyware vendor,
Webroot. He is considered an authority on the topic of vulnerabilities
and patching strategies.

Eschelbeck was also a key figure in the Qualys's involvement in the
Common Vulnerability Scoring System (CVSS) - an evolving standard for
assessing security risks - and in compiling the SANS Top 20, an annual
measure of security vulnerabilities.

Qualys CEO Philippe Courtot was adamant that personnel would be found
from within the company to maintain involvement in the SANS Top 20 -
and in CVSS - a standard the company was strongly committed to.

However, he confirmed that the company had not yet appointed anyone to
oversee the workload, despite appointing an interim CTO in Eschlbeck's
place. Longer term, the company might look outside Qualys itself for a
champion for the Laws analysis.

"One person can't do it all and so you will see more spokespersons,"  
Courtot said.

Eschelbeck, meanwhile, has his hands full at Webroot, as it attempts
to move from a consumer business model to one orientated towards
businesses.



_________________________________
InfoSec News v2.0 - Coming Soon! 
http://www.infosecnews.org 

<Prev in Thread] Current Thread [Next in Thread>
  • [ISN] Qualys vulnerability research put in peril, InfoSec News <=