RE: [Full-Disclosure] no more public exploits
From: Duquette, John (john.duquette_at_eds.com)
Date: 04/27/04
- Previous message: Joshua J. Berry: "[ GLSA 200404-18 ] Multiple Vulnerabilities in ssmtp"
- Maybe in reply to: johnny cyberpunk: "[Full-Disclosure] no more public exploits"
- Next in thread: Dave Sherohman: "Re: [Full-Disclosure] no more public exploits"
- Reply: Dave Sherohman: "Re: [Full-Disclosure] no more public exploits"
- Reply: Yabby: "Re: [Full-Disclosure] no more public exploits"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: Yabby <yabby@softhome.net>, full-disclosure@lists.netsys.com Date: Tue, 27 Apr 2004 12:52:26 -0500
That is a terrible policy to follow. If the vulnerability is real enough
for the vendor to publish a patch, then sysadmins should patch their
systems. Haven't all the recent worms taught people anything?
However, Johnny I'm sorry to see that people who can't control themselves on
the Internet have forced you to stop publishing code. Can't say I blame
you, but I don't have to like it.
> -----Original Message-----
> From: full-disclosure-admin@lists.netsys.com
> [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of Yabby
> Sent: Tuesday, April 27, 2004 1:06 PM
> To: johnny cyberpunk; full-disclosure@lists.netsys.com
> Subject: Re: [Full-Disclosure] no more public exploits
>
>
> Even though I think that the publication of your code might
> have been a couple of weeks too soon: too bad you chose to
> abandon full disclosure. A lot of people do not have the
> skills to transform theoretical vulnerabilities into
> practical exploits. With the lack of proof that the
> vulnerability can really be exploited, a lot of sysadmins
> will decide not to patch, leaving the holes in tact for the
> real blackhats, that have possession of the malicious code anyway....
>
> maarten
>
> > this is an anouncement that i personally have no more intention to
> > publish any
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.netsys.com/full-disclosure-charter.html
>
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Previous message: Joshua J. Berry: "[ GLSA 200404-18 ] Multiple Vulnerabilities in ssmtp"
- Maybe in reply to: johnny cyberpunk: "[Full-Disclosure] no more public exploits"
- Next in thread: Dave Sherohman: "Re: [Full-Disclosure] no more public exploits"
- Reply: Dave Sherohman: "Re: [Full-Disclosure] no more public exploits"
- Reply: Yabby: "Re: [Full-Disclosure] no more public exploits"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|