OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: [PEN-TEST] WebEx security?
From: Alfred Huger (ahSECURITYFOCUS.COM)
Date: Tue Oct 31 2000 - 11:53:14 CST


On Tue, 31 Oct 2000, Erik Tayler wrote:

> A general overview would suffice. Anyone with non-intrusive probing
> capabilities would be able to tell right off the bat.
>
> And no, I didn't break into their site, then draw up the conclusion they
> are insecure.

I would have to disagree with the notion that weak network security on
their site relates to an insecure product. The IT folks are without doubt
not the same people who are writing the application in question. I can
think of a number of vendors who have excellent products in terms of
security and terrible network security....

Bad IT people do not add up to a bad product.