- Bugtraq
Bugtraq is an
electronic mailing list dedicated to issues aboutcomputer security . On-topic issues are new discussions about vulnerabilities, vendor security-related announcements, methods of exploitation, and how to fix them. It is a high-volume mailing list, and almost all new vulnerabilities are discussed there.Bugtraq was created on
November 5 ,1993 by [http://www.zoominfo.com/directory/Chasin_Scott_697360.htm# Scott Chasin] in response to the perceived failings of the existingInternet security infrastructure of the time, particularly CERT. Bugtraq's policy was to publish vulnerabilities, regardless of vendor response, as part of thefull disclosure movement of vulnerability disclosure.Elias Levy , Aleph One, noted in an interview that "the environment at that time was such that vendors weren't making any patches. So the focus was on how to fix software that companies weren't fixing."The mailing list was unmoderated originally, but the signal-to-noise ratio eventually became unacceptably bad. Moderation began on
June 5 ,1995 .Elias Levy moderated the list fromJune 14 ,1996 until he stepped down onOctober 15 ,2001 . David Mirza Ahmad, one of the many co-authors of [http://www.oreilly.com/catalog/1928994709/ Hack Proofing Your Network, Second Edition] , took over from Levy and continued until he stepped down onFebruary 23 ,2006 . [http://www.securityfocus.com/archive/1/425940/30/1860/threaded SecurityFocus ] ] David McKinney, a [http://www.symantec.com/Products/enterprise?c=prodinfo&refId=988&cid=1017 DeepSight threat analyst] atSymantec , took over from Ahmad and is the current moderator. [http://www.securityfocus.com/archive/1/425940/30/1860/threaded SecurityFocus ] ]Bugtraq was originally hosted at Crimelab.com. It was moved to the Brown University NetSpace Project — which has since been reorganized as the [http://www.netspace.org/ NetSpace Foundation] — on
June 5 ,1995 , the same day that its moderation began. In July 1999 it became the property ofSecurityFocus and was moved there. SecurityFocus was acquired in full by Symantec onAugust 6 ,2002 . [http://www.symantec.com/press/2002/n020806.html Symantec Acquisition of SecurityFocus Completed] ]References
External links
* [http://www.securityfocus.com/archive SecurityFocus - Mailing Lists] (Bugtraq is the first mailing list under the Most Popular heading)
* [http://archive.salon.com/tech/feature/2001/08/29/west/index.html Salon - Technology & Business - How do you fix a leaky Net?] (includes mention of Bugtraq)
* [http://www.spirit.com/Network/net0800.html#section-1.1. Spirit - Network Defense - Full Disclosure, or Tales to embarrass Vendors ~ The Good Old Days] (a history of the CERT Advisory CA-93:15fiasco )
Wikimedia Foundation. 2010.