Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen
  1. #1
    bruen@coldrain.net
    Re: [Full-disclosure] Publishing exploit code - what is it good for
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: [Full-disclosure] Publishing exploit code - what is it good for


    Hi Aviram,

    There are two main problems with your analyst friend's position. The
    first is that he has no business deciding for me or anyone else as to
    whether or not my needs are legitimate. I get to decide if I need/want
    something (like exploit code) or not, his arrogance notwithstanding.

    The second point is that he, like most software vendors, have to yet to
    figure out that their products are consumer products and should be treated
    just like automobiles and toys. Consumer product testing is very public.
    Software is the same. We all want to know *exactly* how the product fails,
    just like any other consumer product, no exceptions.

    It is no longer about "full disclosure", it's about being just like
    everyone else. There is no difference between how my software gets
    exploited and how my child safety seat fails.

    cheers, bob



    On Thu, 30 Jun 2005, Aviram Jenik wrote:

    > Hi,
    >
    > I recently had a discussion about the concept of full disclosure with one of
    > the top security analysts in a well-known analyst firm. Their claim was that
    > companies that release exploit code (like us, but this is also relevant for
    > bugtraq, full disclosure, and several security research firms) put users at
    > risks while those at risk gain nothing from the release of the exploit.
    >
    > I tried the regular 'full disclosure advocacy' bit, but the analyst remained
    > reluctant. Their claim was that based on their own work experience, a
    > security administrator does not have a need for the exploit code itself, and
    > the vendor information is enough. The analyst was willing to reconsider their
    > position if an end-user came forward and talked to them about their own
    > benefit of public exploit codes. Quote: " If I speak to an end-user
    > organization and they express legitimate needs for exploit code, then I'll
    > change my opinion."
    >
    > Help me out here. Full disclosure is important for me, as I'm sure it is for
    > most of the people on these two lists. If you're an end-user organization and
    > are willing to talk to this analyst and explain your view (pro-FD, I hope),
    > drop me a note and I'll put you in direct contact.
    >
    > Please note: I don't need any arguments pro or against full disclosure; all
    > this has been discussed in the past. I also don't need you to tell me about
    > someone else or some other project (e.g. nessus, snort) that utilizes these
    > exploits. Tried that. Didn't work.
    >
    > What I need is a security administrator, CSO, IT manager or sys admin that can
    > explain why they find public exploits are good for THEIR organizations. Maybe
    > we can start changing public opinion with regards to full disclosure, and
    > hopefully start with this opinion leader.
    >
    > TIA.
    >
    >


    --
    Dr. Robert Bruen
    Cold Rain Technologies
    http://coldrain.net
    +1.802.579.6288


  2. #2
    Joachim Schipper
    Re: [Full-disclosure] Publishing exploit code - what is it good for
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: [Full-disclosure] Publishing exploit code - what is it good for

    Aviram Jenik wrote:
    > Hi,
    >
    > I recently had a discussion about the concept of full disclosure with one of
    > the top security analysts in a well-known analyst firm. Their claim was that
    > companies that release exploit code (like us, but this is also relevant for
    > bugtraq, full disclosure, and several security research firms) put users at
    > risks while those at risk gain nothing from the release of the exploit.
    >
    > I tried the regular 'full disclosure advocacy' bit, but the analyst remained
    > reluctant. Their claim was that based on their own work experience, a
    > security administrator does not have a need for the exploit code itself, and
    > the vendor information is enough. The analyst was willing to reconsider their
    > position if an end-user came forward and talked to them about their own
    > benefit of public exploit codes. Quote: " If I speak to an end-user
    > organization and they express legitimate needs for exploit code, then I'll
    > change my opinion."


    > What I need is a security administrator, CSO, IT manager or sys admin that can
    > explain why they find public exploits are good for THEIR organizations. Maybe
    > we can start changing public opinion with regards to full disclosure, and
    > hopefully start with this opinion leader.
    >
    > TIA.


    How about anyone who ever hired a pen tester? It's quite impossible to
    have a comprehensive suite of tools without some collaboration, and just
    noting that the vulnerability may exist is not enough in many cases.

    Blackhats may get along with only a handful of exploits, if they're
    willing to try to find targets to match their collection, but a
    pentester should have the collection to match the target.

    This is doubly true if we're not talking about a dedicated pentester,
    but about a sysadmin with a networking/security background who likes to
    verify that the patches did, indeed, work.

    Lastly, I know *I* subscribe to a mailinglist that announces new
    exploits - it gives me a good indication of how long a typical hacker
    takes to code an exploit once the vulnerability is released, plus it
    indicates when patching is past due.

    I'm afraid we're not quite impressive enough, but finding some who are
    should not be too difficult.

    Also, exploits will be distributed, publicly or otherwise - doing it in
    the open means we know what happens when.

    Joachim

  3. #3
    devnull@Rodents.Montreal.QC.CA
    Re: [Full-disclosure] Publishing exploit code - what is it good for
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: [Full-disclosure] Publishing exploit code - what is it good for

    [Because of all the broken autoresponders on bugtraq, the header From:
    is a bitbucket. Use the address in the signature to reach me.]

    >> Quote: " If I speak to an end-user organization and they express
    >> legitimate needs for exploit code, then I'll change my opinion."


    Well, I'm not an end-user organization, but as an end user[%], the
    major benefit I see to full disclosure is that it appears to be close
    to the only thing that has any real success at getting vendors to fix
    bugs. (In general. There certainly are vendors that stay on top of
    things without needing the prod of public exploit disclosure. But they
    are notable by their rarity.)

    [%] "End user" is not the only hat I wear. It's just the one I'm
    wearing here.

    /~\ The ASCII der Mouse
    \ / Ribbon Campaign
    X Against HTML mouse@rodents.montreal.qc.ca
    / \ Email! 7D C8 61 52 5D E7 2D 39 4E F1 31 3E E8 B3 27 4B

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics