RE: [Full-Disclosure] no more public exploits

From: Duquette, John (john.duquette_at_eds.com)
Date: 04/27/04

  • Next message: Baum, Stefan: "AW: [Full-Disclosure] no more public exploits"
    To: Yabby <yabby@softhome.net>, full-disclosure@lists.netsys.com
    Date: Tue, 27 Apr 2004 12:52:26 -0500
    
    

    That is a terrible policy to follow. If the vulnerability is real enough
    for the vendor to publish a patch, then sysadmins should patch their
    systems. Haven't all the recent worms taught people anything?

    However, Johnny I'm sorry to see that people who can't control themselves on
    the Internet have forced you to stop publishing code. Can't say I blame
    you, but I don't have to like it.

    > -----Original Message-----
    > From: full-disclosure-admin@lists.netsys.com
    > [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of Yabby
    > Sent: Tuesday, April 27, 2004 1:06 PM
    > To: johnny cyberpunk; full-disclosure@lists.netsys.com
    > Subject: Re: [Full-Disclosure] no more public exploits
    >
    >
    > Even though I think that the publication of your code might
    > have been a couple of weeks too soon: too bad you chose to
    > abandon full disclosure. A lot of people do not have the
    > skills to transform theoretical vulnerabilities into
    > practical exploits. With the lack of proof that the
    > vulnerability can really be exploited, a lot of sysadmins
    > will decide not to patch, leaving the holes in tact for the
    > real blackhats, that have possession of the malicious code anyway....
    >
    > maarten
    >
    > > this is an anouncement that i personally have no more intention to
    > > publish any
    >
    > _______________________________________________
    > Full-Disclosure - We believe in it.
    > Charter: http://lists.netsys.com/full-disclosure-charter.html
    >

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Baum, Stefan: "AW: [Full-Disclosure] no more public exploits"

    Relevant Pages

    • RE: [Full-disclosure] Our Industry Is Seriously Ethics Impaired
      ... > Why would they lean on any vendor? ... > a vendor to patch it faster doesn't do them near as much good ... Commercial entities who sell vuln audit/scanner/pen-test software ... Ken Williams; Vulnerability Research ...
      (Full-Disclosure)
    • Re: Download.ject - commentary - LONG
      ... > patch recently released by Microsoft. ... > vulnerability in question, but instead is just a partial workaround. ... > Granted these are known security best practices related to Internet ... > a new default browser to users and hope that it will be safe enough. ...
      (microsoft.public.win2000.security)
    • Vulnerability Details for MS02-012
      ... Microsoft released a patch for a denial of service ... vulnerability in the Windows 2000 SMTP component. ... This bug affects all Windows 2000 systems running the SMTP service that have ...
      (Bugtraq)
    • Microsoft Security Bulletin MS01-044
      ... Subject: Microsoft Security Bulletin MS01-044 ... 15 August 2001 Cumulative Patch for IIS ... - A denial of service vulnerability that could enable an attacker ...
      (Bugtraq)
    • [NT] 15 August 2001 Cumulative Patch for IIS
      ... Microsoft has released an important patch for IIS administrators. ... * A denial of service vulnerability that could enable an attacker to ...
      (Securiteam)