Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
A Month of Browser Bugs
Scott Granneman, 2006-07-24

Scott Granneman looks at the virtues and pitfalls of browser fuzzing and the overwhelmingly positive impact it has on the security community.

Comments Mode:
A month of browser bugs 2006-07-24
Chris
Yeah! Appreciate what HD has done in this arena. Kudos!...

[ more ]  [ reply ]
A month of browser bugs 2006-07-24
Anonymous (1 replies)
Great article.......

[ more ]  [ reply ]
Re: A month of browser bugs 2006-07-25
Anonymous
Oh Scott, come on! Stop posting greets to your own articles :D
...

[ more ]  [ reply ]
A month of browser bugs 2006-07-25
Anonymous
Not all fuzzers are created equal. I can fuzz just one aspect of the browser (urls, for example) and claim that I've run a fuzzer against my browser, but if I'm not fuzzing all aspects of input, it's incomplete. My guess is that Microsoft just wasn't complete enough with what they fuzzed.

...

[ more ]  [ reply ]
A month of browser bugs 2006-07-26
Anonymous
This is not just some hacker revealing vulnerabilities. The real value here is that MS is presented with a mechanism to improve their development process and to create better more secure software. Problem is no-one at MS seems to have bought into the idea so their implementation is half-hearted [at ...

[ more ]  [ reply ]
A month of browser bugs 2006-07-26
Anonymous
Taking a quick look at Michael Howard's recent security book "Security Development Lifecycle" where he emphasized the mandatory and extensive fuzzing applied against all applications within the trustworthy iniative. Maybe Mr. Moore has tricks Microsoft has not discovered yet.... or does not want to....

[ more ]  [ reply ]
None for Opera 9 have been found so far... 2006-07-26
Anonymous (1 replies)
one today ;)...

[ more ]  [ reply ]
Re: None for Opera 9 have been found so far... 2006-08-03
Anonymous
and fixed today, with 9.01...
...

[ more ]  [ reply ]
A month of browser bugs 2006-07-31
Anonymous (1 replies)
To call this guy purely a researcher is crap. "He's responsible for the awesome Metasploit Project, an "advanced open-source exploit development platform ... for legal penetration testing and research purposes" that currently contains 143 exploits and 75 different payloads"

if the framework was d...

[ more ]  [ reply ]
Re: A month of browser bugs 2006-08-04
Anonymous
Well I visit the broswer fun blog quite often, and there is all the information of how the bug/exploit works.
The developers just have to patch it. It does benefit all of us.

Btw, good article as always Scott.

P.S. I'm not Scott....

[ more ]  [ reply ]
A month of browser bugs 2006-08-16
Ruben Moreno
He's doing really a great job testint "our" software, but in any case the companies as Scott says should test better than they do....

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus