=================================================================== RCS file: /cvsrepo/anoncvs/cvs/www/security.html,v retrieving revision 1.41 retrieving revision 1.42 diff -u -r1.41 -r1.42 --- www/security.html 1998/03/03 01:22:52 1.41 +++ www/security.html 1998/03/03 01:32:38 1.42 @@ -56,13 +56,13 @@ Another facet of our security auditing process is its proactiveness. In almost all cases we have found that the determination of exploitability is not an issue. During our auditing process we find -many bugs, and endeavor to simply fix them even though exploitability -is not proven. We have fixed many simple and obvious careless -programming errors in code and then only months later discovered that -the problems were in fact exploitable. In other cases we have been -saved from full exploitability of complex step-by-step attacks because -we had fixed one of the steps. An example of where we managed such a -success is the +many bugs, and endeavor to fix them even though exploitability is not +proven. We have fixed many simple and obvious careless programming +errors in code and then only months later discovered that the problems +were in fact exploitable. In other cases we have been saved from full +exploitability of complex step-by-step attacks because we had fixed +one of the steps. An example of where we managed such a success is +the lpd advisory from Secure Networks.

@@ -168,7 +168,7 @@ OpenBSD www@openbsd.org
-$OpenBSD: security.html,v 1.41 1998/03/03 01:22:52 deraadt Exp $ +$OpenBSD: security.html,v 1.42 1998/03/03 01:32:38 deraadt Exp $