, 2002-06-26
Internet Security Systems violated community standards and common sense with its surprise Apache bug announcement.
Expand all |
Post comment
Irresponsible Disclosure
2002-06-27
Please please please get a new UNIX writer! (7 replies)
Please please please get a new UNIX writer! (7 replies)

ISS simply supplying a patch (a patch, BTW, that does not adequately address the bug reported) in no way exhonerates them from any faux pas done. One day after the announcement was made by ISS, exploits for several widely-used OSes running Apache were available. You would have to agree, that, even with a patch, one day is hardly enough time for administrators out in the world to either patch their Apache, or get a binary patch fix from thier respective vendors.
Everyone was suprised by this premature disclosure, and at that point, it opened up many thousands of servers to crack attempts using that vulnerability before an appropriate fix was released. I would expect this from an impatient and excited script kiddie, not from an established and estemed organisation such as ISS and it's ilk.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/91/13318#13318