Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [ISN] Qualys vulnerability research put in peril |
|---|---|
| Date: | Wed, 11 Jan 2006 00:49:26 -0600 (CST) |
http://www.techworld.com/security/news/index.cfm?NewsID=5128 By John E. Dunn Techworld 10 January 2006 Security management vendor Qualys has denied that its innovative Laws of Vulnerability research has been jeopardised by the sudden departure of its key instigator, Gerhard Eschelbeck. The company has confirmed that no individual had been appointed to directly replicate Eschelbeck's work on the research, an analysis of real-world vulnerabilities taken from scans of Qualys's substantial enterprise customer base. The findings for 2005 were announced last November at the Black Hat conference in Las Vegas. Former company CTO and VP of engineering, Eschelbeck, announced before Christmas that he was leaving the company he'd worked at for five years to take up an identical position at anti-spyware vendor, Webroot. He is considered an authority on the topic of vulnerabilities and patching strategies. Eschelbeck was also a key figure in the Qualys's involvement in the Common Vulnerability Scoring System (CVSS) - an evolving standard for assessing security risks - and in compiling the SANS Top 20, an annual measure of security vulnerabilities. Qualys CEO Philippe Courtot was adamant that personnel would be found from within the company to maintain involvement in the SANS Top 20 - and in CVSS - a standard the company was strongly committed to. However, he confirmed that the company had not yet appointed anyone to oversee the workload, despite appointing an interim CTO in Eschlbeck's place. Longer term, the company might look outside Qualys itself for a champion for the Laws analysis. "One person can't do it all and so you will see more spokespersons," Courtot said. Eschelbeck, meanwhile, has his hands full at Webroot, as it attempts to move from a consumer business model to one orientated towards businesses. _________________________________ InfoSec News v2.0 - Coming Soon! http://www.infosecnews.org
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [ISN] Homeland Security helps secure open-source code, InfoSec News |
|---|---|
| Next by Date: | [ISN] Microsoft Plugs 'Critical' E-Mail Server Holes, InfoSec News |
| Previous by Thread: | [ISN] Homeland Security helps secure open-source code, InfoSec News |
| Next by Thread: | [ISN] Microsoft Plugs 'Critical' E-Mail Server Holes, InfoSec News |
| Indexes: | [Date] [Thread] [Top] [All Lists] |