Dailydave mailing list archives

RE: RE: funny comments from Hack IIS6 contest admin


From: "I)ruid" <druid () caughq org>
Date: Tue, 17 May 2005 22:17:54 -0500

On Tue, 2005-05-17 at 16:52 -0400, Roger A. Grimes wrote:
When I say 0-day, I mean public 0-day attacks...like everyone traditionally means...which is [when] a widespread 
exploit happens using a previously undisclosed vulnerability.  The exploit is noticed and then the vulnerability 
found.

I'm not sure what traditions you subscribe to, but in any context I've
ever heard the term '0-day' used, it has had nothing to do with the
scope or severity of the impact it causes, but rather the nature of the
public or community awareness of it.  The types of conditions that you
describe above (among other things, like advisories) are precisely what
cause a vulnerability or exploit to /no longer/ be 0-day.

But I digress, now we're just arguing Symantecs.

-- 
I)ruid, CĀ²ISSP
druid () caughq org
http://druid.caughq.org
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave

Current thread: