lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sun, 06 Feb 2011 17:46:36 +0100
From: Luigi Rosa <lists@...girosa.com>
To: full-disclosure@...ts.grok.org.uk
Subject: Re: vswitches: physical networks obsolete?

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

phocean said the following on 06/02/11 16:58:

> So my worries remain... how do they address this?
> You don't mean that we have to wait for the next 0-day for the VMware
> claim to be proved false? There are coding vulnerabilities everywhere.

We could wait for the next 0day of HP procurve, Cisco Catalyst or Dell
PowerConnect firmware as well ;)

The history of software bugs so far tells us that, until now, the chance to have
a 0day of a firewall is greater than the chance of the 0day of a switch firmware.

I am not telling that switches are bulletproof, I am only talking about probability.



Ciao,
luigi

- -- 
/
+--[Luigi Rosa]--
\

Any small object that is accidentally dropped will hide under a larger object.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk1O0GkACgkQ3kWu7Tfl6ZTahgCfWVHLy/OD/58XOgN2ovanl/dT
LJgAnjtPyYCRujnL/3tzZJ/4K9CcTCF8
=xaty
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ