Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] unreliable vulnerability reports en-masee [was:Re: vulnerability in Symantec products] |
|---|---|
| Date: | Tue, 31 Oct 2006 20:40:49 -0000 |
Gadi Evron wrote:
Nothing really surprises me anymore. The quality of advisories and QA people do seems to be dropping, especially when it comes to File Inclusions. The level of false positives posted in the last couple of weeks is staggering. Folks use Google Code Search to find vulns, and don't notice they are fixed 3 lines above the "bug" and that three lines below, there is another one. Last week, one of these File Inclusion vulns worked only if you disabled two security functions that work by default...
Up to this day, vulnerabilities and exploits would be researched to a level, and released AS-IS. This is fast becoming impracticle.
If the S/N ratio of ADVISORIES rather than ML traffic becomes even lower due to unreliable submissions, our jobs will indeed become much, much harder.
:) Perhaps the antisec/bantown crew have developed a new strategy to try
and shut-down FD by flooding it with useless-but-valid-seeming information?
Just as spammers have moved on from random hashbuster strings to including
chunks of real english text from news reports and books, so the antisec
posters have moved on from furry pr0n and gay lames to real-yet-wrong bug
reports. Subtle, you'll never get even a really good bayesian filter to
discriminate between valid and bogus bug reports!
cheers,
DaveK
--
Can't think of a witty .sigline today....
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: New Flaw in Firefox 2.0: DoS and possible remote code execution, Gouki |
|---|---|
| Next by Date: | [Full-disclosure] Directory listing on B-FOCuS Wireless 802.11b/g ADSL2+ Router by "ECI Telecom LTD", LegendaryZion |
| Previous by Thread: | [Full-disclosure] unreliable vulnerability reports en-masee [was:Re: vulnerability in Symantec products], Gadi Evron |
| Next by Thread: | [Full-disclosure] ZDI-06-035: Novell eDirectory NDS Server Host Header Buffer Overflow Vulnerability, zdi-disclosures |
| Indexes: | [Date] [Thread] [Top] [All Lists] |