Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

April 01, 2004 12:00 AM

Open Source Vulnerability Database Online

Windows IT Pro
InstantDoc ID #42218
Rating: (0)

The Open Source Vulnerability Database (OSVDB), provided by the Open Security Foundation (OSF), is now online and available to the public. OSVDB is an archive of known vulnerabilities and includes vulnerability data pertaining to all platforms. The project was proposed by members of the security community as a means of providing a comprehensive open database that can be used by anyone, including vendors who want to integrate the database into their products. The database is currently supported in Nikto (a Web server security scanner), Snort (an intrusion detection and prevention system), and Nessus (a vulnerability scanner) security products.

The database schema includes an ID number assigned by OSVDB, date when the vulnerability was disclosed, product name, description, vulnerability classifications, the application solutions to the problems, external references for more information (including Bugtraq ID, Arachnids ID, CERT ID, Nessus Script ID, Snort signature ID, and much more) as well as the name of the entity who disclosed the vulnerability.

In December OSF issued a call for volunteers to help develop and maintain the project. Today there over two dozen entities involved with the project include numerous people who help manage the data in the database. Digital Defense provides the server hardware and bandwidth for the project, and according to the OSVDB Web site, Winterforce provides the project with “extensive documentation support, as well as consulting services to help ensure the goals of OSVDB are properly communicated and achieved.”

The project remains open to new volunteers who can help by submitting vulnerability information or by helping to manage data that has already been submitted. The project also wants to establish mirrors of the database and interested parties can contact the group moderators via email.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.