Dailydave mailing list archives

RE: Moot choices, a sort of DD media party


From: Cesar <sqlsec () yahoo com>
Date: Fri, 1 Jul 2005 13:15:49 -0700 (PDT)

Just a comment about this article
http://www.securityfocus.com/news/11230 
I haven't tried the Coverity tool mentined there but i
think naming Oracle as a customer don't have any
benefit, the first thing that comes to my mind is that
the tool doesn't work well (i'm just describing the
message i'm getting, i bet it is a really good tool).
I think the marketing guys from that company should
think what message the public is getting when naming
some customers. It's like saying that the tool was
used to audit Internet Explorer 5.X. Who cares Oracle
is unbreakable.



Cesar.

--- "Aleksander P. Czarnowski" <alekc () avet com pl>
wrote:

Actually a bit related - but instead of operating on
binary level we
have a source code analysis approach presented here:
http://www.securityfocus.com/news/11230

The whole disclosure debate is similar to the one
regarding exploit
publication etc. and I don't get really get it. The
only explanation I
can see it that fact that 99,99 of people who flood
such debates with
emails are not capable of doing real research or
programming but they
still want to be part of game.

Just 2 cents
Cheers,
Aleksander Czarnowski
AVET INS

-----Original Message-----
From: Dave Aitel [mailto:dave () immunitysec com] 
Sent: 1 lipca 2005 16:37
To: dailydave
Subject: [Dailydave] Moot choices, a sort of DD
media party


Reverse engineering patches making disclosure a
moot choice? 
Robert Lemos, SecurityFocus 2005-07-01

When Microsoft released limited information on a
critical 
vulnerability in Internet Explorer last month,
reverse 
engineer Halvar Flake decided to dig deeper....


http://www.securityfocus.com/news/11235

My fav line:

"Many people seem to pour time into the disclosure
debate that should be
spent elsewhere," [Halvar Flake] said. "It's
fruitless and boring and
has been for a few years."

-dave

_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com

https://lists.immunitysec.com/mailman/listinfo/dailydave

_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com

https://lists.immunitysec.com/mailman/listinfo/dailydave




                
__________________________________ 
Discover Yahoo! 
Use Yahoo! to plan a weekend, have fun online and more. Check it out! 
http://discover.yahoo.com/
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: