« Social Security Numbers don't have to be predicted - they are known | Main | Modelling the Security Ecosystem - is exploit availability exceeding patch availability? »

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8345207f669e201157108ab0a970c

Listed below are links to weblogs that reference Exploiting Undercover Vulnerabilities:

Comments

Anton Chuvakin

BTW, Perfect "Pete-read":

http://romeo.copyandpaste.info/txt/ats-policy.txt

"... After the five days have passed, we must conclude that the vendor has issued
some sort of hotfix or a patch to fix the security problem and now the HACKER
sends the bug information, the exploit to the COMMUNITY and possible a
patch too.

Now has security been increased? Do you really think that most of COMMUNITY.
ie: the people that read BUGTRAQ want to patch their servers? No! It is
script kiddies that are waiting for the latest warez, as soon as HACKER
releases this new bug to the COMMUNITY thousands of script kiddies with
little or no skill will start breaking into hundreds of thousands
of boxes and if this bug were genuine, they would! And belive me lots of
boxes would get destroyed.

Now, I ask.. is this a good thing you are doing by posting to the COMMUNITY
all logic says NO!"

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment