Did you see this? http://www.bugtraq.org/advisories/_BSSADV-0000.txt
That's right, "Writing a GUI for Snort: $0; Using OpenSSL and Postgres
for secure database connectivity: $0; Letting anonymous remote users
edit your rulesets: Priceless."
Why bother inserting a bug, when the bugs are inserted for you? :>
-dave
David Maynor wrote:
>On Sat, 2003-12-06 at 21:19, Brass, Phil (ISS Atlanta) wrote:
>
>
>>Owning scanning tools is lame. Owning IDS systems would be very cool.
>>Of course all ISS updates are signed last I checked.
>>
>>
>>
>Agreed. This would only be useful in making a security company look
>really bad.
>"Holy shades of Erik Bloodaxe VulnDev-Man, MOD has owned COMSEC!!"
>
>
_______________________________________________
Dailydave mailing list
Dailydave_at_lists.immunitysec.com
http://www.immunitysec.com/mailman/listinfo/dailydave
Received on Dec 07 2003