Full Disclosure mailing list archives
Re: Microsoft issues out-of-band patch
From: "Bipin Gautam" <bipin.gautam () gmail com>
Date: Fri, 19 Dec 2008 21:21:49 +0545
stop putting so much of attention to 0-day and possible use of it by government to get into a terrorist pc. if breaking into someones pc was a matter of national security importance 0-day may provide a easy leverage but you really dont need a 0-day to get into someones pc, neither you'd need a already existing/known backdoor, neither you'd need to bruteforce into the advisory or a physical access to it. all they need to do is poison a unsigned executable/plugin/update with a backdoor instead, that is being downloaded to the advisory computer over an unencrypted connection if you can control the network gateway or have isp level access. such attacks "could" work regardless of the OS or patch level. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Microsoft issues out-of-band patch n3td3v (Dec 19)
- Re: Microsoft issues out-of-band patch James Rankin (Dec 19)
- Re: Microsoft issues out-of-band patch n3td3v (Dec 19)
- Re: Microsoft issues out-of-band patch Bipin Gautam (Dec 19)
- Re: Microsoft issues out-of-band patch Some Guy Posting To Full Disclosure (Dec 19)
- Re: Microsoft issues out-of-band patch n3td3v (Dec 19)
- Re: Microsoft issues out-of-band patch Ureleet (Dec 21)
- Re: Microsoft issues out-of-band patch Valdis . Kletnieks (Dec 22)
- Re: Microsoft issues out-of-band patch n3td3v (Dec 19)
- Re: Microsoft issues out-of-band patch James Rankin (Dec 19)
- Re: Microsoft issues out-of-band patch n3td3v (Dec 21)
- Re: Microsoft issues out-of-band patch kevin . fielder (Dec 21)
- Re: Microsoft issues out-of-band patch Ureleet (Dec 21)
- Re: Microsoft issues out-of-band patch Ureleet (Dec 21)