Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: SendGate: Sendmail Multiple Vulnerabilities (Race Condition DoS, Memory Jumps, Integer Overflow) |
|---|---|
| Date: | Fri, 24 Mar 2006 15:53:45 -0600 |
Theo,
ISS explained it to us and told us that they had managed to craft an exploit in their lab, but frankly we don't see how it can be practical.
I know the guy who exploited it. He's better than you think he is.
On average it takes him 100 connects to a machine, and he wins the race. Since the child process is a clone of the parent, he gets to try it over and over.
That's the problem, everyone says the race can't be won. If you don't win it, you try again. Eventually you win the race.
And I totally understand that.
If eventually was 1,000,000 attempts, ISS would not be paying him (since he gets paid extra for proven bugs).
If eventually were 1,000,000 attempts, it would still be real.
Their process requires a working exploit before they will disclose. ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
I do think you made a serious mistake in writing an advisory based on the standard boiler plate that many vendors use to make it appear as if the bug is less serious. You avoided saying "This is a remote root" hole. Because it is! ISS told you quite clearly, I am sure. But instead, you went with the standard boiler plate which tries to muddle the situation.
And THAT is why people are upset with you. You should take that criticism to heart and next time not release a muddled boilerplate kind of muddle. Be men. Take a little bit of responsibility -- and people will slightly praise you but most definately not attack you as they are.
But again, I have to say:
We did not attempt to hide this problem.
We didn't try to slip in other changes without saying anything.
Thanks for your comments. Really.
eric
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Quick 'n Easy FTP Server 3.0 pro / lite (buffer overflow vulnerabilities), bifta04 |
|---|---|
| Next by Date: | Re: recursive DNS servers DDoS as a growing DDoS problem, MaddHatter |
| Previous by Thread: | Re: Quick 'n Easy FTP Server 3.0 pro / lite (buffer overflow vulnerabilities), bifta04 |
| Next by Thread: | Re: SendGate: Sendmail Multiple Vulnerabilities (Race Condition DoS, Memory Jumps, Integer Overflow), Gadi Evron |
| Indexes: | [Date] [Thread] [Top] [All Lists] |