2005-11-11

[en] Ubuntu Security Notices

I've converted Ubuntu security advisories into Nessus "local tests".
Nice distro, by the way...


Labels: ,

2005-11-05

[en] Nessus and the art of bullshit

Once upon a time, another of my favourite competitors wanted to check if the Windows machines that he was auditing were up to date with security patches.
For whatever reason, he could not start his laptop on Unix (maybe he just could not install Unix, like so many 3L33T security consultants) so he booted a Knoppix or Auditor Live CD, ran Nessus and said "all clear".

There is one little problem: GPL live CD use GPL Nessus, and nearly all Windows tests are © Tenable, they are not included in the GPL Live CDs, as they are available through the direct feed.
It was no use running the test, we already know the result: no problem.

People actually pay for this kind of "audit". Isn't it amazing?


Labels: ,

[fr] Europa

On disait qu'afin d'acquérir cette maîtrise, le signor avait vendu
son âme au diable, mais Lord Douglas fit remarquer qu'il y avait
belle
lurette que le diable avait renoncé à ce genre de marché, vu
l'abondance extrême de marchandise qui lui était offerte et qu'il
payait à vil prix, avec de la menue monnaie.
Romain Gary, in Europa

Labels: