Active mailing lists / forums for IT security vulnerabilities discussion

I often need to assess vulnerabilities relating to
a) OS (Windows, Redhat Linux & a bit of Solaris x86) &
b) MS Products (Sharepoint, IIS, clustering, .Net Framework, HL7, SQL etc),
c) VMWare products (cloud environment, ESXi, vCenter, vCloud  Director, vShield etc) & 

their relevance/risk level/applicability & the patches/fixes/workarounds needed
in our cloud.  I have to complete the assessments within 3-6 hours.

What are some of the active mailing lists & forums that cover
these topics  that I can raise clarifications & get good & fast
responses?  

Pls indicate those where the responses are publicly viewable & those
that are not.

I may raise clarifications relating to malicious Content issues (iVPN-1
NGX R62),  cross-site scripting, Tipping Point IPS/IDS scanning/
signatures, antivirus (TrendMicro that does deep scans) & various
PenTests / scanning.
sunhuxAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

 
sunhuxAuthor Commented:
including DOS, DDOS/Botnet, application blacklisting/greylisting, SYN flooding,
Trojan as well
0
 
JohnBusiness Consultant (Owner)Commented:
One large security forum is governmentsecurity.org.   Go to the site below:

http://www.governmentsecurity.org/forum/

Also, go to ZDNet and sign up for a selection of newsletters. They often cover security issues and keeps readers apprised of security patches coming up.

Less so, but still valuable is Information Week Daily.

.... Thinkpads_User
0
 
Rich RumbleSecurity SamuraiCommented:
Seclists http://seclists.org/
exploit-db.com http://www.exploit-db.com/
https://isc.sans.edu/diary.html
http://secunia.com/resources/reports/

These are most of the resources I check daily or have a subscription to. Slashdot, ArsTechnica and many AV blogs are useful as well
http://nakedsecurity.sophos.com/
http://krebsonsecurity.com/
http://www.wired.com/threatlevel/
http://www.darkreading.com/
http://arstechnica.com/
-rich
0

Experts Exchange Solution brought to you by ConnectWise

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.