BugTraq
Misinformation in Security Advisories (ASN.1) Feb 16 2004 05:47PM
John Compton (john_compton24 yahoo com) (4 replies)
Re: Misinformation in Security Advisories (ASN.1) Feb 17 2004 03:10PM
Slawek (sgp telsatgp com pl)
Re: Misinformation in Security Advisories (ASN.1) Feb 16 2004 09:45PM
Ivan Arce (ivan arce coresecurity com)
Re: Misinformation in Security Advisories (ASN.1) Feb 16 2004 07:57PM
evol ruiner halo nu
Re: Misinformation in Security Advisories (ASN.1) Feb 16 2004 07:35PM
Simon Brady (simon brady otago ac nz) (1 replies)
Re: Misinformation in Security Advisories (ASN.1) Feb 17 2004 12:17AM
Anthony Saffer (anthonysaffer yahoo com)
> First of all, there is good news for those of you out there who are
> worried about the new ASN.1 vulnerability in Microsoft operating
> systems. It is NOT exploitable to run arbitrary code in anything
> approaching a real-world scenario.

I have to agree with Simon here. Hackers don't deal in "real world"
scenarios but rather specialize in creating exceptional conditions that
wouldn't ever occur under normal operational circumstances. The fact remains
that, regardless of how remote the possibility of a hacker creating the
"right" circumstances on your network/system for an exploit to work, it's
unlikeness doesn't really sooth the nerves of the system admin having to
deal with a breach and recover vital data.

Anthony Saffer [CEO & Founder]
SCS Consulting Services
www.safferconsulting.com
(918) 812-5785

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus