Dailydave mailing list archives

Re: Funny note here on a worm


From: Jason <security () brvenik com>
Date: Sun, 01 May 2005 14:31:06 -0400



Gadi Evron wrote:
This disturbs me.

Not surprising really.


If there is reliable information that a worm is being developed, do you
sit on that and wait for the world to have to deal with it?


We all know it will show up, posting such claims without said
information is skiddie like. "I have a dozen exploits but can't release
them".
These kind of things would cause panic, generally speaking (not this
incident).

My point is how do you know said information is not available? We all know there are many exploits floating around for many microsec vulns. When a company with an obligation to clients becomes aware of a _specific_ issue it is prudent for them to take action on that information. ( within the bounds of the law )

There is a difference between knowing and _knowing_ and that is apparently a subtlety that escapes you.

A side note, I propose that all 0day/sec/microsec/nanosec now be called random bits floating around the psychic friends network. They can be referred to as PFN tools.

< snippage irrelevant mutterings >

Did you receive that information from the proper people that are
attempting to prevent the spread of a worm?


No, he got it from the web site, your web site which you have nothing to
do with, naturally.

Get with the program Gadi. Dave got it from the snort.org site, Kyle jumps on it and claims marketing heads talking. I didn't say word one about the initial posts. I piped up when people started throwing conjecture around as if they can know.

>
>
>>Was the release of that worm prevented?
>
>
> How should I know? If it was, isn't it silly to make such claims?
> Another will show up anyway.

Now you are starting to get it. I fear this is more sarcasm than clue though.

< useless gibberish snipped >

I found the snip entertaining myself. Only thing keeping me thinking there is more to the story is that I know the people involved and don't think they would make those claims without good reason. It is just not like them to do it.

_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: