Live data from Hacker News

Show HN: Enter your URL and view CVEs affecting your stack over last 6 months

secalerts.co

1–10 of 50 posts

Re: Show HN: Enter your URL and view CVEs affecting your stack over last 6 months

#2
i don't need to provide my (potentially vulnerable) production URL to whoever-you-might-be in order to identify the last 6 months of vulnerabilities - I can just google for that.

Submitting your site to this is just asking for trouble.

Re: Show HN: Enter your URL and view CVEs affecting your stack over last 6 months

#3

i don't need to provide my (potentially vulnerable) production URL to whoever-you-might-be in order to identify the last 6 months of vulnerabilities - I can just google for that. Submitting your site to this is just asking for trouble.

This just seems like a mailing list for CVE alerts for popular software. If you put in HN, it'll say that it failed to detect the stack, and then ask you to choose your software and then enter your email to receive alerts.

It's kind of clever marketing, giving people a sense that they're going to get a security audit in exchange for an email address.

Re: Show HN: Enter your URL and view CVEs affecting your stack over last 6 months

#4

i don't need to provide my (potentially vulnerable) production URL to whoever-you-might-be in order to identify the last 6 months of vulnerabilities - I can just google for that. Submitting your site to this is just asking for trouble.

Anyone can (and people are) just scan the internet for hosts on port 80/443 and unless your site uses virtual hosts and has no HTTPS certificates issued to one of your domains, it's going to be discovered and probed exactly like this site does anyways. The difference is real adversaries are doing it without you knowing.

Re: Show HN: Enter your URL and view CVEs affecting your stack over last 6 months

#5
post #3

i don't need to provide my (potentially vulnerable) production URL to whoever-you-might-be in order to identify the last 6 months of vulnerabilities - I can just google for that. Submitting your site to this is just asking for trouble.

This just seems like a mailing list for CVE alerts for popular software. If you put in HN, it'll say that it failed to detect the stack, and then ask you to choose your software and then enter your email to receive alerts. It's kind of clever marketing, giving people a sense that they're going to get a security audit in exchange for an email address.

The first URL I entered (coop.co.uk) was actually pretty awesome, it detected Varnish and showed a critical CVE from last week. That’s cool.

I hope that if you subscribe, the site regularly rescans your stack and realised if it’s changed. Otherwise it’s just a mailing list subscription that becomes out of date and therefore not useful.

Re: Show HN: Enter your URL and view CVEs affecting your stack over last 6 months

#6

i don't need to provide my (potentially vulnerable) production URL to whoever-you-might-be in order to identify the last 6 months of vulnerabilities - I can just google for that. Submitting your site to this is just asking for trouble.

I’d suggest that running a vulnerable production service is asking for trouble!

My web logs are full of automated scanners. Once when I ran a vulnerable version of Wordpress it got discovered and pwned very quickly. No need to enter the URL in any website ;)

Re: Show HN: Enter your URL and view CVEs affecting your stack over last 6 months

#7

i don't need to provide my (potentially vulnerable) production URL to whoever-you-might-be in order to identify the last 6 months of vulnerabilities - I can just google for that. Submitting your site to this is just asking for trouble.

This is the textbook definition of security by obscurity.

Re: Show HN: Enter your URL and view CVEs affecting your stack over last 6 months

#8
This is a nice addendum to the "Let Us Identify Your Stack" style web services tho I guess some of them might already provide this.

It does have the somewhat negative effect of making potentially vulnerable websites more visible to lower order hackers (I'm assuming more proficient ones have automated discovery tools like this anyway).

Re: Show HN: Enter your URL and view CVEs affecting your stack over last 6 months

#10
post #7

i don't need to provide my (potentially vulnerable) production URL to whoever-you-might-be in order to identify the last 6 months of vulnerabilities - I can just google for that. Submitting your site to this is just asking for trouble.

This is the textbook definition of security by obscurity.

It's not even that. There's no obscurity here. This is security by pretending.
Post reply on HN