Re: Disclosure Debate - yet again

From: Matthew Ramadanovic (matthew.ramadanovic_at_YALE.EDU)
Date: 10/08/04

  • Next message: Kurt: "Re: Disclosure Debate - yet again"
    Date:         Fri, 8 Oct 2004 17:31:28 -0400
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    >Can we get consensus, even if just among the current group in this
    >discussion, that "user friendly" PoCs are bad?

    Absolutely, if 1% of competent people write malicious code yet only 1% of
    those people could write it from scratch it is quite logical that the first
    step should be to eliminate the risk created by the 99%.

    While it is fun to see the exploit first hand, I've never accomplished
    anything really productive by following an exploit recipe. By now there have
    been so many that even that small amount of fun has worn off.

    -Matt

    Matt Ramadanovic
    Network Administrator
    Yale University Investments Office
    mailto:matthew.ramadanovic@yale.edu

    --
    NTBugtraq Editor's Note:
    Want to reply to the person who sent this message? This list is configured such that just hitting reply is going to result in the message coming to the list, not to the individual who sent the message. This was done to help reduce the number of Out of Office messages posters received. So if you want to send a reply just to the poster, you'll have to copy their email address out of the message and place it in your TO: field.
    --
    

  • Next message: Kurt: "Re: Disclosure Debate - yet again"

    Relevant Pages

    • Re: subroutine stack and C machine model
      ... who'd be pretty fun to work with. ... There's some pretty competent folks here, ... notable exceptions) are an extremely self-selected group, ...
      (comp.lang.c)
    • Re: subroutine stack and C machine model
      ... On 14 Nov 2009 at 9:37, Seebs wrote: ... who'd be pretty fun to work with. ... You and a couple of other anonymous trolls were pretty much the bulk ... There's some pretty competent folks here, ...
      (comp.lang.c)
    • Re: subroutine stack and C machine model
      ... but fun? ... Competent, no question. ... and it turns out that pedantry makes ... appears to demonstrate substantial expertise with the language fairly ...
      (comp.lang.c)
    • Re: Installing Gas Fire
      ... fun, isn't it? ... In this instance you don't know that I am competent, ... Qualifications & experience are what count. ... lot less inclined to practise DIY, preferring to get someone in to do ...
      (uk.rec.motorcycles)
    • Re: Installing Gas Fire
      ... Andy B burbled... ... but baselessly casting aspersions on something with no proof is such ... fun, isn't it? ... In this instance you don't know that I am competent, ...
      (uk.rec.motorcycles)