RE: [Full-Disclosure] Multiple Backdoors found in eEye Products (IRISand SecureIIS)

From: Barrie Dempster (barrie_at_reboot-robot.net)
Date: 12/30/04

  • Next message: Thierry Carrez: "[Full-Disclosure] [ GLSA 200501-09 ] xzgv: Multiple overflows"
    To: full-disclosure@lists.netsys.com
    Date: Thu, 30 Dec 2004 09:36:07 +0000
    
    
    
    

    I'd have to agree with the eEye statement on this one. You sent out an
    advisory without disclosing the details, which offers no real benefit to
    anyone. Many people consider this responsible disclosure but that also
    requires you to notify the vendor (there were no @eeye.com's in your
    "to" list but there were a couple of press mailboxes).

    You didn't contact eEye, you didn't release details, you used an
    anonymous address and failed to mention or credit any of the other guys
    in your "testing team", This can only lead us to believe that the
    advisory is fake and only intended to generate bad press for eEye. I
    personally don't care about eEye's PR rating but I do care about the
    level of noise on these lists and I do care about backdoor-ed commercial
    products that are in common use. You may have an issue with eEye and see
    this as revenge. However, I doubt you also have an issue with the many
    admins who probably have spent their holiday season investigating these
    claims, when there are likely more pressing matters to address, such as
    a large stock of alcohol.

    Show us details, or be quiet. If you intended to embarrass eEye the plan
    backfired as any competent professional on this list (there are a few -
    I've heard stories about them) would see this as a shameful attempt and
    would be laughing at you, not eEye.

    Seasons greetings to eEye and all Full Disclosure subscribers - even you
    "Lance Gusto".

    With Regards..
    Barrie Dempster (zeedo) - Fortiter et Strenue

      http://www.bsrf.org.uk

    [ gpg --recv-keys --keyserver www.keyserver.net 0x96025FD0 ]

    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: Thierry Carrez: "[Full-Disclosure] [ GLSA 200501-09 ] xzgv: Multiple overflows"

    Relevant Pages

    • Re: Press Release Response
      ... >technique than what eEye came up with, ... from the data that Microsoft gives within their advisories." ... is this practice of Full Disclosure effective? ... not the advisory of the vulnerability. ...
      (NT-Bugtraq)
    • Re: Can we afford full disclosure of security holes?
      ... Can we afford full disclosure of security holes? ... > Wouldn't it have been much better for eEye to give the details ... the original hole. ...
      (Bugtraq)
    • Re: Can we afford full disclosure of security holes?
      ... Can we afford full disclosure of security holes? ... >I believe that less revealing eEye advisory would have saved a lot ... >Unlike the eEye advisory, the Microsoft advisory on the IIS ...
      (Bugtraq)
    • RE: Can we afford full disclosure of security holes?
      ... Can we afford full disclosure of security holes? ... I believe that less revealing eEye advisory would have saved a lot ... Sure, releasing code may make it easier for script kiddies, but trying to ...
      (Bugtraq)
    • [Full-Disclosure] list noise
      ... I also care about noise, and responding to stupid mails makes it worse. ... Every time people send stupid mails like the rm file thing, and people reply to the list, the author was successful in filling the list with crap for a day or so. ... Multiple Backdoors found in eEye Products ... > level of noise on these lists and I do care about backdoor-ed commercial ...
      (Full-Disclosure)

    Loading