Full Disclosure mailing list archives

Re: [Secure Network Operations, Inc.] Full Disclosure != Exploit Release


From: Florian Weimer <Weimer () CERT Uni-Stuttgart DE>
Date: Wed, 29 Jan 2003 17:50:30 +0100

Strategic Reconnaissance Team <recon () snosoft com> writes:

It is possible to prove a vulnerability exists by releasing well written
advisories.  Because of this fact, proof of concept code (exploit
source) is not a requirement for the education of the possibly
vulnerable.

If you don't publish such code, you will eventuall kill projects like
Nessus and Snort by starvation.  Is this your intention?

-- 
Florian Weimer                    Weimer () CERT Uni-Stuttgart DE
University of Stuttgart           http://CERT.Uni-Stuttgart.DE/people/fw/
RUS-CERT                          fax +49-711-685-5898
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: