Content deleted Content added
Jericho347 (talk | contribs) m add motto |
Rescuing 0 sources and tagging 2 as dead.) #IABot (v2.0.9.5 |
||
(9 intermediate revisions by 7 users not shown) | |||
Line 5:
}}
The '''Open Sourced Vulnerability Database''' ('''OSVDB''') was an independent and open-sourced [[vulnerability database]]. The goal of the project was to provide accurate, detailed, current, and unbiased technical information on [[Information security|security]] vulnerabilities.<ref>{{Cite web|last=Rosencrance|first=Linda|date=2004-04-16|title=Brief: Vulnerability database goes live|url=https://www.computerworld.com/article/2563666/brief--vulnerability-database-goes-live.html|access-date=2020-08-15|website=Computerworld|language=en}}</ref> The project promoted greater and more open collaboration between companies and individuals. The database's motto was "Everything is Vulnerable".<ref>{{cite web |title=Biased software vulnerability stats praising Microsoft were 101% misleading |url=https://www.csoonline.com/article/2226625/biased-software-vulnerability-stats-praising-microsoft-were-101--misleading.html |accessdate=20 May 2020}}</ref>
==History==
The project was started in August 2002 at the [[Black Hat Briefings|Blackhat]] and [[DEF CON]] Conferences by several industry notables (including [[H. D. Moore]], rain.forest.puppy, and others). Under mostly-new management, the database officially launched to the public on March 31, 2004.<ref>{{cite news |url=https://www.networkworld.com/article/3053613/open-source-vulnerabilities-database-shuts-down.html |title=Open-source vulnerabilities database shuts down |first=Jon |last=Gold |work=Network World |date=7 April 2016 |access-date=22 January 2020}}</ref> The original implementation was written in PHP by Forrest Rae (FBR). Later, the entire site was re-written in Ruby on Rails by David Shettler.
The [[Open Security Foundation]] (OSF) was created to ensure the project's continuing support.
On 5 April 2016, the database was shut down,
As of January 2012, vulnerability entry was performed by full-time employees of Risk Based Security,<ref>{{Cite web|title=Homepage|url=https://www.riskbasedsecurity.com/|access-date=2020-08-15|website=RBS|language=en-US}}</ref> who provided the personnel to do the work in order to give back to the
==Process==▼
▲==Process==
▲As of January 2012, vulnerability entry was performed by full-time employees of the OSF. Every new entry included a title, description, solution (if known), classification data, references, products, and creditee.
Originally, vulnerability disclosures posted in various security lists and web sites were entered into the database as a new entry in the New Data Mangler (NDM) queue. The new entry contained only a title and links to the disclosure. At that stage the page for the new entry didn't contain any detailed description of the vulnerability or any associated metadata. As time permitted, new entries were analyzed and refined, by adding a description of the vulnerability as well as a solution if available. This general activity was called "data mangling" and someone who performed this task a "mangler". Mangling was done by core or casual volunteers. Details submitted by volunteers were reviewed by the core volunteers, called "moderators", further refining the entry or rejecting the volunteer changes if necessary. New information added to an entry that was approved was then available to anyone browsing the site.
==Contributors==
Some of the key people that volunteered and maintained '''OSVDB''':
*
*
* Kelly Todd a.k.a. Lyger (Officer of OSF, Moderator)
* David Shettler (Officer of OSF, Developer)
* Daniel Moeller (Moderator)
* Forrest Rae (Developer)
Other volunteers who have helped in the past include:<ref>{{Cite web |date=2014-05-02 |title=OSVDB: Open Sourced Vulnerability Database |url=http://osvdb.com/contributors |access-date=2024-08-06 |archive-url=https://web.archive.org/web/20140502042016/http://osvdb.com/contributors |archive-date=2 May 2014 }}</ref>
▲* [[Chris Sullo]] (Moderator)
* Steve Tornio (Moderator)
* Zach Shue (Moderator)
* Alexander Koren a.k.a. ph0enix (Mangler)
* Carsten Eiram a.k.a. Chep (Moderator)
* Marlowe (Mangler)
* Travis Schack (Mangler)
* Susam Pal (Mangler)
* Christian Seifert (Mangler)
* Zain Memon
== References ==
Line 40 ⟶ 48:
== External links ==
* [https://blog.osvdb.org/ OSVDB Blog]{{Dead link|date=August 2025 |bot=InternetArchiveBot |fix-attempted=yes }}
* [https://www.riskbasedsecurity.com/ Risk Based Security]
|