Firewall Wizards mailing list archives

Re: Penetration testing via shrinkware


From: "tqbf" <ashland () pobox com>
Date: Fri, 18 Sep 1998 16:24:10 -0400 (EDT)

it could reasonably be expected to check for is infinite.  Scanners can never be
complete, because the space of possible mis-configurations and buggy software
knows no bounds.

You have a misconception about what a scanner is. The purpose of a scanner
is no more to discover all possible misconfigurations and vulnerabilities
than the purpose of a firewall is to stop all possible attacks. 

-----------------------------------------------------------------------------
Thomas H. Ptacek                          Network Security Research Team, NAI
-----------------------------------------------------------------------------
                                 "If you're so special, why aren't you dead?"



Current thread: