Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Buzzword Bonanza
Elias Levy, SecurityFocus 2000-05-01

Security companies can make headlines by using the right jargon, even when it's wrong.

Comments Mode:
A couple of comments 2000-05-01
Anonymous (3 replies)
First, Mr Levy starts out with:

"A backdoor is normally understood in computer security circles to refer to a system vulnerability

deliberately put in place by system designers or operators such that it would allow them to bypass

normal security checks. The "wemilo" password discovered in the Cart32 shopping cart software last

week is an example of a genuine backdoor."

Then Mr Levy goes on to say:

"The first one is the fact that the documented "piranah" web account created when you install this package has an undocumented default password. "

Finally:

"Neither of these vulnerabilities fits the description of a backdoor. "

Sounds to me as if the default password is, in fact, a "backdoor", according to the definition that Mr Levy himself put forth. In fact, Mr Levy points out that:

"The "wemilo" password discovered in the Cart32 shopping cart software last week is an example of a genuine backdoor."

Perhaps one default password constitutes a backdoor and another does not. If this is the case, Mr Levy, can you please point out why?

My final comment is that there is a lot of talk about the media spreading FUD (fear, uncertainty, doubt) through their sensationalizing of stories and events regarding computer or network security. Mr Levy's article has a subtitle that begins by denouncing "security companies", yet the only example that he puts forth is a statement made by ISS. Certainly, Mr Levy, there are other security companies out there...

H. Carvey

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/25/1565#1565
Re: A couple of comments 2000-05-01
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]> (1 replies)
Re: A couple of comments 2000-05-01
Anonymous (1 replies)
Re: A couple of comments 2000-05-01
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]> (3 replies)
Re: A couple of comments 2000-05-02
Anonymous (1 replies)
Re: A couple of comments 2000-05-02
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]>
Re: A couple of comments 2000-05-02
Anonymous (2 replies)
Re: A couple of comments 2000-05-02
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]> (1 replies)
Re: A couple of comments 2000-05-02
Anonymous (1 replies)
Re: A couple of comments 2000-05-02
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]>
Re: A definition from an observer 2000-05-03
Anonymous (1 replies)
Re: A definition from an observer 2000-05-05
Anonymous
Re: A couple of comments 2000-05-02
Anonymous (1 replies)
Re: A couple of comments 2000-05-03
Anonymous
A couple of comments 2000-05-02
Matthew Pemble <matthew (at) idrach (dot) com [email concealed]>
A couple of comments 2000-05-05
Anonymous
Glad to see this... 2000-05-01
Anonymous
Simple solution. 2000-05-04
Anonymous
Not back door by Def. used 2000-05-05
Anonymous
Microsoft did the same at Win2K 2000-05-05
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus