Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
The value of vulnerabilities
Jason Miller, 2006-03-07

There is value in finding vulnerabilities. Yet many people believe that a vulnerability doesn't exist until it is disclosed to the public. We know that vulnerabilities need to be disclosed, but what role do vendors have to make these issues public?

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
Re: What Value? 2006-03-20
infamous41md
If you can place an arbitrary value at an arbitrary address, that IS remote code execution.

Why are they paying for vulns? Because security is "cool" now. Also, for certain companies, it makes sense for them to pay idefense for their services. Example, Adobe. If researchers know that idefen...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus