[Full-Disclosure] Re: exploits, good exploits

From: John Q Public (johnqpublic2323_at_mailvault.com)
Date: 07/22/03

  • Next message: Jason: "Re: [Full-Disclosure] IIS/Outlook Web Access.."
    To: pen-test@securityfocus.com
    Date: Mon, 21 Jul 2003 23:25:30 -0400 (EDT)
    
    

    This is a MIME encoded message.

    --=_a72578003709bb3ae01d2c23962a64f9
    Content-Type: text/plain
    Content-Transfer-Encoding: 7bit

    0ddly, I didn't get a copy of the original message in my inbox - but I
    have a few things to say about this thread. First off, if you are
    getting your exploits at public distribution sites such as:

     http://packetstormsecurity.nl/exploits20.shtml
     http://www.k-otik.com/exploits/
     http://www.securiteam.com/exploits/
     etc..

    then you are already *several* steps behind the curve. Climbing up the
    chain, you will see release points such as exploit authors/groups
    websites. Higher still, you have private exploit distribution networks
    such as trading in IRC channels and private mailing lists (I run a
    private 0day mailing list myself, less technical than 0daydigest but
    more action). In these cases the way you get involved is if you
    contribute something - you need to offer something new. Beyond the
    aforementioned, you pretty much just have the exploit developers
    themselves. My recommendation is learn to find your own bugs and write
    your own code.

    Though, it's interesting - there are now commercial grade exploits being
    offered for sale from companies!

       $995 http://www.immunitysec.com/CANVAS/
     $15000 http://www.coresecurity.com/products/coreimpact/index.php

    These packages are similar but include different exploits and framework
    so it would be hard to compare the two. Expect this short list (2) to
    grow to dozens in the coming years, including opensource/free versions
    I'm sure (but I hope not).

    jqp

    --- Frank Boldewin <frank.boldewin@gmx.de> wrote:
    > canvas has some 0day exploits and i think it is worth a buy,
    > but another good product is core impact.
    > they made a good product full of reliable exploits, for the
    > latest bugs in major daemons. it's not very cheap, but worthy
    > for that what u might searching for.
    >
    > cheers,
    > frank
    >
    --=_a72578003709bb3ae01d2c23962a64f9--

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Jason: "Re: [Full-Disclosure] IIS/Outlook Web Access.."

    Relevant Pages

    • Re: [opensuse] Implementation of Private & Secure Mail Server & Mailing Lists Manager
      ... I'm not talking about public mailing lists. ... The task is to setup closed, private, secure mailing list for limited ... Decrypt using an Encrypt key? ...
      (SuSE)
    • Re: [opensuse] Implementation of Private & Secure Mail Server & Mailing Lists Manager
      ... I'm not talking about public mailing lists. ... The task is to setup closed, private, secure mailing list for limited number ... Mail Server has the encryption key for the each Mailing List it handles. ...
      (SuSE)
    • Re: A Product Design Invitation
      ... He's created his own little private newsgroup. ... apparently nobody's told him about majordomo mailing lists, ... mailing lists, yahoo BBSs, googlegroups private groups, wwwboard ...
      (sci.electronics.design)
    • [UNIX] Pipermail Permissions Problem
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... mailing list archives without requiring any special security privileges. ... If you have private Mailman mailing lists and user logins on the ...
      (Securiteam)
    • Re: sun java vs Fedora
      ... The problem isn't with the ipv6. ... I am now wondering if it could be the transparent proxy issue that ... has also been discussed in the java mailing lists. ... mentioned that I am in a private ip address space using an address ...
      (Fedora)