Dailydave mailing list archives

Re: bleeding nessus [was: Re: Funny note here on a worm]


From: Gadi Evron <ge () linuxbox org>
Date: Tue, 03 May 2005 20:27:30 +0400

I would highly encourage you to write a NASL script and submit it
to us. You'll see that we maintain your copyright, and will also
maintain your code if we find issues or false positives with it
over time. Tenable's only policy (besides not accepting just poorly
written NASL scripts, stuff that has high false positive rates,
.etc) is that we won't take NASL scripts for recently disclosed
vulnerabilities. Looking through the last 30 NASLs added, there
were at least two non-Tenable folks contributing to the GPL feeds.

I don't want to be a kiddie and say something without backing it up with
proof/code, but I have a proposition. You take that back.
Call me a kiddie if you like but going down to the details is becoming
inflammatory. If you can send here unsubstantiated claims, there is no
reason for me to provide with my evidence when I do the same.

I believe (I am naturally, delusional) that you (Tenable) did indeed put
your name on plugin(s) you did not write. Check me on it as again, I am
naturally wrong by saying this.

How do I think that I feel that I know that? Because I do search the web
for plugins (which is difficult as you try and kill anything that is not
Tenable controlled and release only what suits you), and there have been
some occasion(s) where a certain plugin later appeared on your site with
the wrong name on it. Obviously by mistake.

Now, as I don't back this up but rather raise a voice of concern and
suspicion, hoping beyond hope that you will put my mind at ease, just
responding to your public claims....
How about we do a full audit of your 7K plugins? :) How about we don't?
How about you prove me wrong, in my many faults? How about you
substantiate your claims and tell us what plugins you deny, when and why
before I send in my data?

Point is, I appreciate and even look up to open source companies, and I
really like people who try to make money - nothing wrong with it. What I
dislike is people who try to do what you do - which is basically "let's
kill the community so that we can make a buck" and "create a dependency
on our services by not allowing others to contribute on a large scale".

And putting down snort.. now that was low.

        Gadi.
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: