AV/FW Adoption Sudies

Valdis.Kletnieks at vt.edu Valdis.Kletnieks at vt.edu
Thu Jun 10 20:46:34 UTC 2004


On Thu, 10 Jun 2004 13:30:41 PDT, Eric Rescorla said:

> [0] Note that this doesn't require that the chance of finding
> any particular bug upon inspection of the code be very low
> high, but merely that there not be very deep coverage of
> any particular code section.

Right.  However, if you hand the team of white hats and the team of black hats
the same "Chatter has it there's a 0-day in Apache's mod_foo handler"....

Note that the rumored 0-day doesn't even have to exist - one has to wonder
how many of the bugs found in Windows by all color hats were inspired by
Allchin's comment under oath that there was an API flaw in Windows so
severe that publishing the API could endanger national security.....

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 226 bytes
Desc: not available
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20040610/f5f9ffa4/attachment.sig>


More information about the NANOG mailing list