We don’t allow questions seeking recommendations for software libraries, tutorials, tools, books, or other off-site resources. You can edit the question so it can be answered with facts and citations.
Closed 4 months ago.
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
接受
或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
发布评论
评论(1)
大多数漏洞往往会在邮件列表中公布,例如由 SecurityFocus 托管的 Bugtraq。您将找到开源项目的单独邮件列表,尽管此处并未讨论大多数漏洞,也没有太多的披露。
您还可以找到 MITRE-CVE 和 OSVDB 作为有用的来源。您所在国家/地区的 CERT 也是如此,尽管在大多数情况下您会发现 发出的警报US-CERT 足以遵循。
Most vulnerabilities tend to get announced on mailing lists like the Bugtraq which is hosted by SecurityFocus. You'll find a separate mailing list for Open Source projects, although most vulnerabilities aren't discussed here, and neither are a lot of disclosures.
You'll also find MITRE-CVE and OSVDB as useful sources. So is the case with your country's CERT, although in most cases you'll find that the alerts issued by US-CERT are sufficient enough to follow.