Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Maynor reveals missing Apple flaws
Robert Lemos, SecurityFocus 2007-03-01

ARLINGTON, VA. -- Security researcher David Maynor got some measure of vindication at the Black Hat DC Conference this year.

Comments Mode:
Maynor reveals missing Apple flaw 2007-03-01
Anonymous
Maynor reveals missing Apple flaw 2007-03-01
Anonymous
And the bottom line is ... 2007-03-02
Anonymous
Maynor reveals missing Apple flaw 2007-03-02
David Taylor (2 replies)
Re: Maynor reveals missing Apple flaw 2007-03-02
Anonymous (1 replies)
Apple Fanboys, Grow Up. 2007-03-04
Anonymous
The reason Maynor waited 6 months was to demonstrate it at Blackhat. Duh.

If there was nothing to find, then how how did apple magically find and fix the bugs for Maynor to reverse the patches and write exploit code?

What did Maynor do, look in his crystal ball and guess? Look fanboys, Occams razor. Look it up.

BTW it's very common and also ethical to release a PoC that just crashes the target as opposed to running exploit code. Crash... you can see what the DoS pushed onto the stack and tell that it would be possible to run arbitrary code. Meanwhile, script kiddies won't be 0wning every apple at the local starbucks.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11445/34368#34368
You got it all wrong Robert 2007-03-05
Anonymous (1 replies)
Re: You got it all wrong Robert 2007-03-05
Robert Lemos (1 replies)
Re: Re: You got it all wrong Robert 2007-03-05
Anonymous (3 replies)
Maynor reveals missing Apple flaws 2007-03-05
Anonymous (1 replies)
Re: Maynor reveals missing Apple flaws 2007-03-06
Russell Morris
Where are the documents? 2007-03-14
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus