Re: Public disclosure of discovered vulnerabilities

From: Stephen Sprunk (stephen_at_sprunk.org)
Date: 05/18/05


Date: Wed, 18 May 2005 13:38:29 -0500


"Andi Kleen" <freitag@alancoxonachip.com> wrote in message
news:p733bsm7z0t.fsf@verdi.suse.de...
> "Stephen Sprunk" <stephen@sprunk.org> writes:
> > In contrast, one vendor I worked with would fix security bugs and
> > ship patches (without telling customers what they fixed) as quickly
>
> That seems like a bad strategy because software patches can be
> usually relatively easy reverse engineered. Disassembling a big
> program is quite tough because it is so much code, but just looking
> at some differences to an earlier version of the image is much easier.
>
> So a blackhat just needs to watch the new patches and then use the
> exploits before all the customers know about it and updated their
> systems. Worst of both ways.

I was deliberately omitting details because I thought they'd obscure the
point, however it appears that was a bad idea.

The vendor in question releases code only as a complete system image,
and they do so every few weeks. Each release has hundreds, if not
thousands, of changes to it and only a handful (if any) are related to
security. An attacker would have to disassemble the code for every
release, track down every change, determine whether or not each had
anything to do with security, and then come up with an exploit before
most customers had upgraded. Certainly possible, but not terribly
likely. And, if someone did publish details of a hole that was found
this way, all the vendor would need to do in return is publish the
notice immediately (instead of sitting on it for six months) since the
code with the fix was already released.

S

-- 
Stephen Sprunk      "Those people who think they know everything
CCIE #3723         are a great annoyance to those of us who do."
K5SSS                                             --Isaac Asimov


Relevant Pages

  • [NEWS] Wonderware SuiteLink Denial of Service Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... Vendor Information, Solutions and Workarounds ... Core sends the advisory draft to Wonderware support team. ...
    (Securiteam)
  • [Full-Disclosure] Security Industry Under Scrutiny: Part 3
    ... > varying degrees of 'faith' in the security industry. ... site admins and other whitehats. ... > architect would be notifying the software vendor alone... ... Full disclosure isn't so much a tool to get vunerability information ...
    (Full-Disclosure)
  • [NT] Internet Explorer Zone Elevation Restrictions Bypass and Security Zone Restrictions Bypass (MS0
    ... Get your security news from a reliable source. ... Internet Explorer Zone Elevation Restrictions Bypass and Security Zone ... Vendor Information, Solutions and Workarounds: ... Core sends an advisory ...
    (Securiteam)
  • RE: Vendor wants remote control of our Servers and Workstations
    ... Of course the age-old problem with security is that ... Vendor has significant access to your internal ... this vendor uses the same method to support a number ... customer and makes significant changes ... ...
    (Security-Basics)
  • Security researchers organization
    ... of security researchers, plain and simple. ... better than the vendor itself. ... industry, telecommunications industry and banking industry has ( ... These are all common ideals we can agree and act upon, ...
    (NT-Bugtraq)