Dailydave mailing list archives

Re: Exploits matter.


From: Ilfak Guilfanov <ig () hexblog com>
Date: Thu, 08 Oct 2009 10:47:19 +0200


Sorry for my ignorance, are NULL pointer dereference bugs exploitable today?

Steve Shockley said the following on 7/10/2009 15:56:
On 10/6/2009 10:12 AM, dave wrote:
But if you are like me, you are thinking "But it's still worth it". And
here's why: Without exploits, you have no way to know what matters. Or,
more realistically, what doesn't matter. I.E. in this case, 64 bit
computers are not going to be exploited with SMBv2 any time soon, of at
all. Since enterprises skipped Vista and use 64 bit for their Windows
2008 servers, SMBv2 didn't hurt as badly as you would expect.

Doesn't that just mean that *you* can't exploit it right now?  Not 
trying to insult your haxxor skillz, but a few years ago you couldn't 
get a virus via email or Word, and null pointer dereference bugs could 
never be exploited.
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


-- 
Best regards,
  Ilfak                            mailto:ig () hexblog com
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: