, SecurityFocus 2001-11-09
Five computer security firms join Microsoft to set an official standard for limiting disclosure of software security holes
Expand all |
Post comment
Shocking developments
2001-11-09
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (2 replies)
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (2 replies)
Such a policy for disclosure already exists
2001-11-09
Dumky (1 replies)
Dumky (1 replies)
Such a policy for disclosure already exists
2001-11-10
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]>
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]>
...on second thought...Kudos!
2001-11-09
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (1 replies)
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (1 replies)
So what would force Microsoft to patch these holes if exploits are not published?
2001-11-10
Rafal Sybilla-Leszczynski (1 replies)
Rafal Sybilla-Leszczynski (1 replies)
So what would force Microsoft to patch these holes if exploits are not published?
2001-11-12
Anonymous
Anonymous
Microsoft have no server monopoly: this may reduce their share
2001-11-12
Kirsten Bayes (kirruth@hushmail)
Kirsten Bayes (kirruth@hushmail)

these companies haven't released an advisory in some time,these companies or their employees host sites which offer auditing utilities. The only way these companies can ensure that their utilities and those of their employees are used for "good" purposes is to severely restrict access to them.
Among the sites which may be influenced by this are
nmrc.org, packetfactory.net, phrack, etc. These are sites maintained by employees of the companies involved with Microsoft. If you use these utilities in the performance of your job, I suggest you download and stockpile them immediately.
Unfortunately, information and utilities from these sites may need to be considered untrusted in the future.
There is no way for us to verify whether the employee's integrity has been breached by the company they work for or if they have been "reached" by Microsoft.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/articles/281/8679#8679