Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Busting the Worm Writers
Tim Mullen, 2003-11-24

Microsoft deserves praise for offering a cash reward to catch people who criminally exploit their bugs.

Comments Mode:
Busting the Worm Writers 2003-11-24
dlEEb (1 replies)
Busting the Worm Writers 2003-11-29
jarhead
Hats Off To Mullen 2003-11-24
MULLET HEAD (1 replies)
Hats Off To Mullen 2003-11-25
Anonymous (2 replies)
Hats Off To Mullen 2003-11-25
Anonymous
Hi, Sweetheart! 2003-11-25
Penguinisto (1 replies)
Oh my... 2003-11-28
Anonymous (1 replies)
Why yes, yes there is. 2003-11-28
Penguinisto (1 replies)
Why yes, yes there is. 2003-12-03
Anonymous
Busting the Worm Writers 2003-11-24
Anonymous
Busting the Worm Writers 2003-11-24
Anonymous (1 replies)
Busting the Worm Writers 2003-11-25
Anonymous
Busting the Worm Writers 2003-11-24
Anonymous
Busting the Worm Writers 2003-11-24
Anonymous (1 replies)
Busting the Worm Writers 2003-11-25
Anonymous (1 replies)
Remote vs. local exploits 2003-11-26
Anonymous
Busting the Worm Writers 2003-11-24
Anonymous
Life... anyone!? 2003-11-25
Anonymous (3 replies)
Life... anyone!? 2003-11-25
Anonymous
Life... anyone!? 2003-11-25
Anonymous
Life... anyone!? 2003-11-26
Stefan (1 replies)
Life... anyone!? 2003-11-26
Anonymous (1 replies)
Life... anyone!? 2003-11-27
Stefan (1 replies)
Life... anyone!? 2003-11-28
Anonymous
Typical Responses 2003-11-25
John Carroll (4 replies)
Typical Responses 2003-11-25
Penguinisto
Typical Responses 2003-11-25
Anonymous
Typical Responses 2003-11-26
Oregon
I'll believe it when I see it... 2003-11-26
Anonymous
abused housewife 2003-11-25
aeonflux
Actually, it's a semi-good idea, but will it work? 2003-11-25
Penguinisto
You seem kinda paranoid lately, Timster...

Personally, I think it's about time Microsoft started owning up to the mess it inadvertantly helped to create. It does have some benefits (if they'd up it to $500K they may get further, but it's a start.)

I can see a small bit of opportunity for abuse to anyone crafty enough to pull it off (Release virus laced w/ hints implicating some sucker, plant virus toolkit on a public computer in his neighborhood, gin up some fake IRC logs, call the cops, collect a Big Fat Check(tm)...) Otherwise, it's a nice way to get the script kiddies to rat on each other and at least do something to curb the copycats who can only modify the scripts that others have written.

Err, notice that I said "script kiddies" up there. Good luck catching any of the real talent with it... they usually don't brag in IRC. But like you said - as part of an overall strategy, it ain't bad.

Now all we gotta do is see these so-called efforts towards cleaning up the mess internal to Windows, the flaws and bad practices that helped facilitate worms and viruses so easily in the first place.

This brings me to your final statement. It is indeed a people problem, but certain OEMs certainly aren't helping by applying superficial solutions to fundamental flaws, ne?

/P

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/199/23859#23859
Busting the Worm Writers 2003-11-26
Anonymous
Busting the Worm Writers 2003-11-26
Pee
Busting the Worm Writers 2003-11-26
Rob McQuillen
How old is Mullen? 2003-11-27
Please do not use HTML in your replies. HTML tags will be filtered. (1 replies)
How old is Mullen? 2003-11-28
JHC (1 replies)
How old is Mullen? 2003-11-28
Captain Kirk hahaha (1 replies)
How old is Mullen? 2003-11-28
JHC
Busting the Worm Writers 2003-12-01
Michal
Busting the Worm Writers 2003-12-02
Rihards







 

Privacy Statement
Copyright 2009, SecurityFocus