Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Microsoft
[Top] [All Lists]

RE: Microsoft Vulnerabilities ARE being reported to Microsoft

Subject: RE: Microsoft Vulnerabilities ARE being reported to Microsoft
Date: Wed, 22 Dec 2004 15:01:05 -0500
paul//

Do you really care what MS thinks?
My way of going around things....

1. Find the bug
2. Inform the software maker
3. Release the bug/vulnerability and a proof of concept(POC/exploit) to a
full disclosure list.

Paul... If you can compromise SP2, lets see it. Release a POC.

Take it from there.

Happy Holidays Everyone-



-----Original Message-----
From: Paul [mailto:paul@greyhats.cjb.net] 
Sent: Monday, December 20, 2004 10:29 PM
To: focus-ms@securityfocus.com
Subject: Microsoft Vulnerabilities ARE being reported to Microsoft




If you came here looking for a vulnerability, you will be dissapointed,
because this is simply a message. Contrary to popular opinion, I do disclose
my vulnerabilities to Microsoft before release. They do not resond to any of
my emails so I assumed they either 1) didn't care, or 2) were taking
considerable action to patch these vulnerabilities. The Microsoft statement
that I do not disclose the vulnerabilities to them is untrue and is probably
just an attempt by Microsoft to make me look bad because of their own
incompetence. I will continue to work towards a secure operating system
because that is what we security professionals strive to accomplish.

PS: Microsoft, I have found a way to compromise SP2 by writing a file to
anywhere on the victim's computer without user interaction. As always, I
will email you with the details of the vulnerability.

---------------------------------------------------------------------------
---------------------------------------------------------------------------


---------------------------------------------------------------------------
---------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>