[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: CONTENT DECISION: Presence of Services or Applications (SA)



On Tue, Aug 03, 1999 at 08:52:05PM -0500, Gene Spafford wrote:
> I really do not like the idea behind this category.   We might as
> well include most MS-based protocols, and most TCP services.   The
> fact that a service is present and has a history of being a point of
> entry on some systems is not a vulnerability.    That's like saying
> that the presence of computers tends to enable hacking -- take away
> the computers, and you no longer have break-ins!

Hear, hear!

> 
> --spaf
> 

-- 
Aleph One / aleph1@underground.org
http://underground.org/
KeyID 1024/948FD6B5 
Fingerprint EE C9 E8 AA CB AF 09 61  8C 39 EA 47 A8 6A B8 01 

Page Last Updated or Reviewed: May 22, 2007