Dailydave mailing list archives

"A bounds check on the exploitability index" (Bas Alberts)


From: Dave Aitel <dave () immunityinc com>
Date: Wed, 04 Feb 2009 13:56:55 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Immunity's latest paper can be found here.
http://www.microsoft.com/downloads/details.aspx?FamilyID=0c6e07b5-43ce-4da1-873e-2d604106574c

To quote from the download page:
"""


        Overview

Launched in October 2008 by the Microsoft Security Response Center
(MSRC), the Microsoft Exploitability Index is designed to provide
additional information to help customers better prioritize the
deployment of Microsoft security updates. This index provides
customers with guidance on the likelihood of functioning exploit code
being developed for vulnerabilities addressed by Microsoft security
updates. So, just how valuable is such an exploitability index and how
should it be used? To help answers these questions, Immunity, Inc., a
well respected player in the vulnerability research community, has
conducted a third-party analysis of the exploitability index and
presented its case in the form of a white paper.

"""

- -dave
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFJieT3tehAhL0gheoRAt8/AJ9sGLNs1ulHLcD4ynqu8VOfhIuiygCdHaz7
8hfRfsKwC+Pkm4xf+IORPVM=
=gosS
-----END PGP SIGNATURE-----

_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: