Dailydave mailing list archives
RE: RE: funny comments from Hack IIS6 contest admin
From: "Roger A. Grimes" <roger () banneretcs com>
Date: Tue, 17 May 2005 16:52:18 -0400
Somewhat true. But basically, you would have people reporting unauthorized activities on their boxes that were fully patched and properly configured. A 0-day vulnerability might not be known, but most don't go undiscovered for long...as they end up attacking high-value targets that are being monitored by good sys admins. When I say 0-day, I mean public 0-day attacks...like everyone traditionally means...which is a widespread exploit happens using a previously undisclosed vulnerability. The exploit is noticed and then the vulnerability found. In that described category, there has been only one (and I can't even remember its name or the exploit) of a widespread attack on a previously undisclosed bug. -----Original Message----- From: I)ruid [mailto:druid () caughq org] Sent: Tuesday, May 17, 2005 12:03 PM To: Roger A. Grimes Cc: Dave Aitel; dailydave Subject: RE: [Dailydave] RE: funny comments from Hack IIS6 contest admin On Sat, 2005-05-14 at 21:31 -0400, Roger A. Grimes wrote:
First, there haven't been many 0-day exploits against W2K3 and IIS 6 (if any), and not that many against Windows products at all since 2000 was released.
I find this statement vastly amusing. How exactly would you know? 0day, by definition[1], is publicly undisclosed. The only way you can know for certain that 0day for a given target exists is for you to posses it yourself. By their nature, you don't know for certain if there haven't been many of them (or they don't exist at all). [1] http://en.wikipedia.org/wiki/0day (paragraph 3) -- I)ruid, C²ISSP druid () caughq org http://druid.caughq.org _______________________________________________ Dailydave mailing list Dailydave () lists immunitysec com https://lists.immunitysec.com/mailman/listinfo/dailydave
Current thread:
- RE: funny comments from Hack IIS6 contest admin, (continued)
- RE: funny comments from Hack IIS6 contest admin Roger A. Grimes (May 14)
- Re: funny comments from Hack IIS6 contest admin Anthony Zboralski (May 14)
- Re: RE: funny comments from Hack IIS6 contest admin Dave Aitel (May 14)
- RE: RE: funny comments from Hack IIS6 contest admin Roger A. Grimes (May 14)
- Re: RE: funny comments from Hack IIS6 contest admin Bas Alberts (May 14)
- Re: RE: funny comments from Hack IIS6 contest admin Steve Lord (May 15)
- RE: RE: funny comments from Hack IIS6 contest admin I)ruid (May 17)
- RE: funny comments from Hack IIS6 contest admin Roger A. Grimes (May 14)
- RE: RE: funny comments from Hack IIS6 contest admin Roger A. Grimes (May 15)
- Re: RE: funny comments from Hack IIS6 contest admin Holden Williamson (May 15)
- RE: RE: funny comments from Hack IIS6 contest admin Roger A. Grimes (May 17)
- Re: RE: funny comments from Hack IIS6 contest admin H D Moore (May 17)
- Re: funny comments from Hack IIS6 contest admin Holden Williamson (May 18)
- Re: Re: funny comments from Hack IIS6 contest admin H D Moore (May 18)
- Re: RE: funny comments from Hack IIS6 contest admin H D Moore (May 17)
- RE: RE: funny comments from Hack IIS6 contest admin I)ruid (May 17)
- RE: funny comments from Hack IIS6 contest admin Roger A. Grimes (May 14)
- RE: RE: funny comments from Hack IIS6 contest admin Roger A. Grimes (May 18)
- Re: RE: funny comments from Hack IIS6 contest admin Jan Muenther (May 18)
- Re: RE: funny comments from Hack IIS6 contest admin Mark (May 18)
- Re: RE: funny comments from Hack IIS6 contest admin Dave Aitel (May 18)
- Re: RE: funny comments from ack IIS6 contest sadmin Jack (May 18)
- Music to hack to Steve Lord (May 18)
- Re: RE: funny comments from Hack IIS6 contest admin Jan Muenther (May 18)
