Dailydave mailing list archives

RE: RE: funny comments from Hack IIS6 contest admin


From: "Roger A. Grimes" <roger () banneretcs com>
Date: Tue, 17 May 2005 16:52:18 -0400

Somewhat true.  But basically, you would have people reporting unauthorized activities on their boxes that were fully 
patched and properly configured.  A 0-day vulnerability might not be known, but most don't go undiscovered for 
long...as they end up attacking high-value targets that are being monitored by good sys admins.

When I say 0-day, I mean public 0-day attacks...like everyone traditionally means...which is a widespread exploit 
happens using a previously undisclosed vulnerability.  The exploit is noticed and then the vulnerability found.

In that described category, there has been only one (and I can't even remember its name or the exploit) of a widespread 
attack on a previously undisclosed bug. 

-----Original Message-----
From: I)ruid [mailto:druid () caughq org] 
Sent: Tuesday, May 17, 2005 12:03 PM
To: Roger A. Grimes
Cc: Dave Aitel; dailydave
Subject: RE: [Dailydave] RE: funny comments from Hack IIS6 contest admin

On Sat, 2005-05-14 at 21:31 -0400, Roger A. Grimes wrote:
First, there haven't been many 0-day exploits against W2K3 and IIS 6 
(if any), and not that many against Windows products at all since 2000 
was released.

I find this statement vastly amusing.  How exactly would you know?
0day, by definition[1], is publicly undisclosed.  The only way you can know for certain that 0day for a given target 
exists is for you to posses it yourself.  By their nature, you don't know for certain if there haven't been many of 
them (or they don't exist at all).

[1] http://en.wikipedia.org/wiki/0day (paragraph 3)

--
I)ruid, C²ISSP
druid () caughq org
http://druid.caughq.org
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: