Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Exploit Code on Trial
Kevin Poulsen, SecurityFocus 2003-11-23

Security pros gathering at a Stanford University Law School conference on responsible vulnerability disclosure Saturday harmonized on the principle that vendors should be privately notified of holes in their products, and given at least some time to produce a patch before any public disclosure is made. But there was pronounced disagreement on the question of whether or not researchers should publicly release proof-of-concept code to demonstrate a vulnerability.

Comments Mode:
Exploit Code on Trial 2003-11-24
Anonymous
Screw the vendors 2003-11-24
Anonymous (2 replies)
Screw the vendors 2003-11-25
Rodrigo Otaviano <rodrigo (at) otaviano (dot) com [email concealed]>
Exploit Code on Trial 2003-11-24
Bob Radvanovsky
Exploit Code on Trial 2003-11-24
Anonymous
Exploit Code on Trial 2003-11-24
TW
I have, and will continue to use exploit code in my day to day job. I am tasked with rating the threat that new vulnerabilities can have against my corporation. I test and process known exploits for several reasons: To confirm that the vulnerability is valid against MY systems as configured, and to see if it is possible to build an IDS signature for the specific exploit code\vuln. I can do all of this before I even get a patch from the vendor. Hence reducing my risk.

Often the source of the exploit code I receive is NOT available to the public (so called 0-day) and stuff that never surfaces on public sites. However we test ALL published code as soon as we can. I find it extremely helpful to me, and my peers to have such code available. Having working exploits is the easiest way for me to get the risk across to the teams that have to do the patching. A higher risk, insures a faster patch pipeline deployment.

TW

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/7511/23836#23836
Exploit Code on Trial 2003-11-25
Leif Ericksen
Exploit Code on Trial - final word 2003-11-25
Anonymous (1 replies)
Exploit Code on Trial 2003-11-25
Camel
Loss of money 2003-11-29
bl0rf
Exploit Code on Trial 2003-12-02
Anonymous
Exploit Code on Trial 2003-12-02
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus