Penetration Testing mailing list archives

Re: [PEN-TEST] WebEx security?


From: Alfred Huger <ah () SECURITYFOCUS COM>
Date: Tue, 31 Oct 2000 09:53:14 -0800

On Tue, 31 Oct 2000, Erik Tayler wrote:

A general overview would suffice. Anyone with non-intrusive probing
capabilities would be able to tell right off the bat.

And no, I didn't break into their site, then draw up the conclusion they
are insecure.


I would have to disagree with the notion that weak network security on
their site relates to an insecure product. The IT folks are without doubt
not the same people who are writing the application in question. I can
think of a number of vendors who have excellent products in terms of
security and terrible network security....

Bad IT people do not add up to a bad product.


Current thread: