Re: Time For New Security Package? (was Re: new iss stuff)

Tom Fitzgerald (fitz@wang.com)
Tue, 10 May 1994 22:33:52 -0400 (EDT)

> I have in mind a framework which would allow people to
> contribute scripts to check for specific holes, so once the framework
> is in place anyone could contribute new checks very easily.  

This subject came by once before....  I like this idea, but with two
comments.  First, it'd be better to fit something like this into COPS,
since COPS already does dozens of things you'd want such a test suite to
do, and COPS already has lots of useful name-recognition.  Second, Gene
Spafford mentioned that he had someone already working on something like
this, so I'd be careful not to duplicate effort.

Given that, I have a pile of SCO Unix hole-tests I'd be happy to donate.

-- 
Tom Fitzgerald   Wang Labs   Lowell MA, USA   1-508-967-5278   fitz@wang.com
I swear, white people get stranger every year.