, SecurityFocus 2002-01-16
A U.K. security expert is preparing to unveil a trove of serious vulnerabilities in Oracle's database products. Can the company redefine 'unbreakable' in time?
Expand all |
Post comment
14 evaluations missed what 1 guy found...
2002-01-16
Anonymous (5 replies)
Anonymous (5 replies)

The reality is, Litchfield is an expert who had incentives to try and find problems: he is writing a tool that's supposed to evaluate (scan) Oracle. If you run Nessus against your site and it shows no problems, does that mean you're completely safe? No. If you have other problems, which assuredly you do, does that also imply Nessus (or Nsat or Ncat or eEye or whatever) is useless? No.
The more realistic problem is that these 14 evaluations were all too similar. So running more of the same is likely to generate results that are more of the same. If you're really trying to find problems, then you need to increase the probability that new tools (evaluations) are looking for different things so the space of things you're considering and testing is more/wider.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/articles/309/9947#9947