Not reading pen testing reports is a known and hard to patch vulnerability. Should we give it a CVE, @xme wonders http://blog.rootshell.be/2015/02/26/the-evil-cve-cve-666-666-report-not-read/ …
-
-
Replying to @bartblaze
@bartblaze@virusbtn@xme Compliance-based testing fuels the industry. It's also its curse.1 reply 0 retweets 0 likes -
Replying to @william_knows
@william_knows@virusbtn@xme Good point. Which compliances would that be, any specifics? Thanks.2 replies 0 retweets 1 like -
Replying to @bartblaze
@bartblaze@william_knows@virusbtn True! Pentesting is not a bullet point in a checklist!1 reply 0 retweets 0 likes -
Replying to @xme
@xme@bartblaze@virusbtn I think it can be if it encourages people to do one. The key is having the requirement to act on its results.2 replies 0 retweets 0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.