Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Internet Explorer 0day exploit Jul 10 2007 05:09AM
Thor Larholm (seclists larholm com) (1 replies)
Re: Internet Explorer 0day exploit Jul 10 2007 03:53PM
Gadi Evron (ge linuxbox org) (1 replies)
Re: Internet Explorer 0day exploit Jul 15 2007 02:40AM
Dragos Ruiu (dr kyx net) (1 replies)
Re: Internet Explorer 0day exploit Jul 15 2007 02:41AM
Gadi Evron (ge linuxbox org) (1 replies)
Re: Internet Explorer 0day exploit Jul 18 2007 08:37AM
Chris Stromblad (cs outpost24 com) (2 replies)
Re: Internet Explorer 0day exploit Jul 18 2007 06:37PM
Bigby Findrake (bigby ephemeron org) (1 replies)
Re: Internet Explorer 0day exploit Jul 18 2007 08:17PM
Chris Stromblad (cs outpost24 com)
Re: Internet Explorer 0day exploit Jul 18 2007 04:53PM
Zow Terry Brugger (zow llnl gov) (1 replies)
Re: Internet Explorer 0day exploit Jul 18 2007 08:12PM
Chris Stromblad (cs outpost24 com) (1 replies)
Re: Internet Explorer 0day exploit Jul 20 2007 09:08PM
Chad Perrin (perrin apotheon com) (1 replies)
RE: Internet Explorer 0day exploit Jul 21 2007 03:22PM
Ken Kousky (kkousky ip3inc com) (2 replies)
RE: Internet Explorer 0day exploit Jul 24 2007 02:54PM
Roger A. Grimes (roger banneretcs com)
RE: Internet Explorer 0day exploit Jul 24 2007 05:37AM
Hugo van der Kooij (hvdkooij vanderkooij org)
On Sat, 21 Jul 2007, Ken Kousky wrote:

> Zero day is a serious misnomer from vendors that suggest that the counting
> of time an exposure is known BY THE GOOD GUYS is some kind of trigger date
> when in reality, many serious exploits are know BY THE BAD GUYS so the day
> zero is really months or maybe years prior to the disclosure or notification
> date. Look at the WMF vulnerability that caused a mad rush to patch it once
> the good guys were put on notice. In this case, the vulnerability had been
> present in Windows products since the early 90s and according to Kapersky
> Labs there was even malware being sold that took advantage of it long before
> there was even day zero notification.

I reserve the word 0day to issues that have been found through exploits.

So a 0day exploit is an exploit out in the field were the vulnerability
is/was not publicly known before the exploit was found.

As such it would be a very rough indication of the score of good guys
(writing advisories) and the bad guys (writing exploits).

Hugo.

--
hvdkooij (at) vanderkooij (dot) org [email concealed] http://hugo.vanderkooij.org/
This message is using 100% recycled electrons.

Some men see computers as they are and say "Windows"
I use computers with Linux and say "Why Windows?"
(Thanks JFK, for the insight.)

[ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus