Full Disclosure mailing list archives
Re: [NETRAGARD SECURITY ADVISORY] [Cambium Group, LLC. CAMAS Content Management System -- Multiple Critical Vulnerabilities][NETRAGARD-20070820]
From: Valdis.Kletnieks () vt edu
Date: Wed, 25 Feb 2009 09:59:12 -0500
On Wed, 25 Feb 2009 09:01:26 EST, Smoking Gun said:
Snake oil at it's finest. You may recall Netragard has a pay for play scheme working where they never disclose any code. This works to anyone's advantage as a trump card when you think about it on a psychological warfare like scale. "We found a tumor somewhere in your body however, we're choosing not to tell you about how we found it, nor where it is."
You got that wrong in a subtle and important way. What Kevin said:
Proof of concept code exists but is not provided as to not increase CAMAS users overall risk levels.
isn't like the doctor telling you "We found a tumor in you but we won't tell *you* what it is". It's more like "We found a tumor, and we won't tell your employer, because they might try to cancel your medical insurance when they find out how much this is going to cost". And *that* threat model (retaliation by employers/friends/society) is a well-understood threat model, and is *why* medical records are in general considered confidential.
Attachment:
_bin
Description:
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- [NETRAGARD SECURITY ADVISORY] [Cambium Group, LLC. CAMAS Content Management System -- Multiple Critical Vulnerabilities][NETRAGARD-20070820] Netragard Advisories (Feb 24)
- Re: [NETRAGARD SECURITY ADVISORY] [Cambium Group, LLC. CAMAS Content Management System -- Multiple Critical Vulnerabilities][NETRAGARD-20070820] Smoking Gun (Feb 25)
- Re: [NETRAGARD SECURITY ADVISORY] [Cambium Group, LLC. CAMAS Content Management System -- Multiple Critical Vulnerabilities][NETRAGARD-20070820] Valdis . Kletnieks (Feb 25)
- <Possible follow-ups>
- Re: [NETRAGARD SECURITY ADVISORY] [Cambium Group, LLC. CAMAS Content Management System -- Multiple Critical Vulnerabilities][NETRAGARD-20070820] bobby . mugabe (Feb 24)
- Re: [NETRAGARD SECURITY ADVISORY] [Cambium Group, LLC. CAMAS Content Management System -- Multiple Critical Vulnerabilities][NETRAGARD-20070820] Smoking Gun (Feb 25)