Dailydave mailing list archives

RE: RE: funny comments from Hack IIS6 contest admin


From: "I)ruid" <druid () caughq org>
Date: Tue, 17 May 2005 11:03:10 -0500

On Sat, 2005-05-14 at 21:31 -0400, Roger A. Grimes wrote:
First, there haven't been many 0-day exploits against W2K3 and IIS 6 (if
any), and not that many against Windows products at all since 2000 was
released. 

I find this statement vastly amusing.  How exactly would you know?
0day, by definition[1], is publicly undisclosed.  The only way you can
know for certain that 0day for a given target exists is for you to
posses it yourself.  By their nature, you don't know for certain if
there haven't been many of them (or they don't exist at all).

[1] http://en.wikipedia.org/wiki/0day (paragraph 3)

-- 
I)ruid, CĀ²ISSP
druid () caughq org
http://druid.caughq.org
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave

Current thread: