Previously I mentioned several web sites which are useful for determining current vulnerabilities. I firmly believe that leakedin.com and pastebin.com are useful for determining vulnerabilities however they are not the most useful for looking for information unless you're looking for something specific such as customer information. Other sites are far better at performing the task of identifying vulnerabilities such as the US Cert site and Symantec. The National Vulnerability Database provided by US Cert is likely one of the best sites for reviewing vulnerabilities. This site contains virtually every known vulnerability and is easily searched.
Being tasked with finding vulnerabilities I would utilize the Symantec and US Cert sites in order far more often then others. Having a good reliable source for locating vulnerabilities is likely one of the most important things a security professional will do. Having a credible source with valuable and easy to find information is critical. I believe that the US Cert and Symantec sites are likely some of the most credible sources available for vulnerability information.
No comments:
Post a Comment