OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Depp, Dennis (deppdOSTI.GOV)
Date: Thu Sep 06 2001 - 12:39:13 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Please also don't forget that some developers are human and make mistakes!

    Dennis Depp, MCSE
    Sr Systems Administrator
    SAIC, deppdsaic.com
    "I've been trying for some time to develop a life style that doesn't require
    my presence." ? cartoonist Gary Trudeau

    -----Original Message-----
    From: Ichinin [mailto:ichininSWIPNET.SE]
    Sent: Friday, August 17, 2001 9:54 PM
    To: win2ksecadviceLISTSERV.NTSECURITY.NET
    Subject: Re: IIS Web Server Condom

    Howard Marsh wrote:
    > Could so many security vulnerabilities be fixed so simply?

    Yes.

    Because of..

    1) Some developers are lazy A-holes and just shovle the
    variables into a DB or app without checking validity, hence
    the great number of insecure products.

    2) Some people does not understand security or are ignorant
    or choose the ostridge approach to security.

    /Ichinin

    _____________________________________________________________________
    ** TO UNSUBSCRIBE, send the command "UNSUBSCRIBE win2ksecadvice"
    ** FOR A WEEKLY DIGEST, send the command "SET win2ksecadvice DIGEST"
    SEND ALL COMMANDS TO: listservlistserv.ntsecurity.net

    _____________________________________________________________________
    ** TO UNSUBSCRIBE, send the command "UNSUBSCRIBE win2ksecadvice"
    ** FOR A WEEKLY DIGEST, send the command "SET win2ksecadvice DIGEST"
    SEND ALL COMMANDS TO: listservlistserv.ntsecurity.net