Full Disclosure mailing list archives
RE: Publishing exploit code - what is it good for
From: "James C Slora Jr" <Jim.Slora () phra com>
Date: Thu, 30 Jun 2005 13:50:32 -0400
I have used public exploits for: 1. Verifying that the manufacturer's recommendations have been followed and that they work. This was invaluable in the first few rounds of Microsoft RPC patches a couple of years ago - some patches appeared to have installed correctly but the machines were still vulnerable. They would not have been patched successfully without exploit testing. Yes, the public exploit code helped lead to widespread malware outbreaks, but those first few bugs were so blatant that black hats could exploit them easily anyway and the outbreaks still would have happened. Witness the continuing success of those vectors. The public exploits at least let us test to see if we were prepared. 2. Developing methods to detect the exploits. 3. Understanding the exploitation process better. This way I can make the hard sell on taking systems off line for patching with the appropriate urgency. 4. Blocking appropriate attack vectors (and thinking of other potential vectors), and making sure the attacks don't get through. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: Publishing exploit code - what is it good for, (continued)
- Re: Publishing exploit code - what is it good for Anders B Jansson (Jun 30)
- Re: Publishing exploit code - what is it good for bugtraq (Jun 30)
- Re: Publishing exploit code - what is it good for Ill will (Jun 30)
- Re: Publishing exploit code - what is it good for Gary E. Miller (Jun 30)
- Re: Publishing exploit code - what is it good for Steve Milner (Jun 30)
- Re: Publishing exploit code - what is it good for Matt . Carpenter (Jun 30)
- Re: Publishing exploit code - what is it good for Michael Holstein (Jun 30)
- Re: Publishing exploit code - what is it good for Jason Coombs (Jun 30)
- Re: Publishing exploit code - what is it good for Kenneth Ng (Jun 30)
- Re: Publishing exploit code - what is it good for KF (lists) (Jun 30)
- Re: Publishing exploit code - what is it good for Jason Coombs (Jun 30)
- RE: Publishing exploit code - what is it good for James C Slora Jr (Jun 30)
- Re: Publishing exploit code - what is it good for Thomas Reinke (Jun 30)
- Re: Publishing exploit code - what is it good for John Madden (Jun 30)
- Re: Publishing exploit code - what is it good for Skip Carter (Jun 30)
- Re: Publishing exploit code - what is it good for Damian Menscher (Jun 30)
- RE: Publishing exploit code - what is it good for Glenn.Everhart (Jun 30)
- Re: Publishing exploit code - what is it good for Joxean Koret (Jun 30)
- RE: Publishing exploit code - what is it good for Matt Huston (Jun 30)
- Re: Publishing exploit code - what is it good for John Horn (Jun 30)
- RE: Publishing exploit code - what is it good for Todd Towles (Jun 30)
- RE: Publishing exploit code - what is it good for Marvin Simkin (Jun 30)
