On GameSpot: Thinking about buying an Xbox 360?
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 15 of 31:
Next »
« Previous
So What
Ok so it's sort of dickish that HDM published this exploit, but guess what, this attack is already in the wild. Moore and |)ruid just have big ole brass balls for releasing this exploit code publicly.

The fact is the cat is out of the bag, anyone with a modicum of skills can create a similar exploit in a couple hours or even less, and could have done so since at least three days ago when Halvar posted his initial conjecture (ok maybe 1-2 days if you are a pessimist/optimist).

Regardless of what you think about that (I am pretty ambivalent about it, unless you think Halvar is smarter then every blackhat), there is no real harm in it.

As I said, this exploit has been already seen in the wild, the code is out there, if anything this just further illustrates the need to patch your systems. people who are going to exploit this are either already doing so or are preparing to do so very shortly, and with the money at stake for successfully exploiting this you can bet they aren't waiting around for some public exploit code to be released when its so easy to roll their own.

P.S. Ryan, Stop being such a hate monger about this and making it look like the security community is full of petty infighting, Tom apologized for his (I believe) honest mistake. Matasano isn't exactly a no name outfit trying to garner publicity for themselves. I'm sure Kaminsky is pretty upset, to put it mildly, but in the end mistakes happen, lets all grow up. Hell I could even defend Halvar talking about the bug by saying that security through obscurity ain't the best. This just sped up peoples patch cycles a bit, it's not the end of the world.
Posted by: KStads   Posted on: 07/23/08  (Edited: 07/23/2008 @ 10:42) You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Irresponsible and evil  Stan57 | 07/23/08
Quote: "What positive will come of this?"  dunn@... | 07/24/08
Assumption  Stan57 | 07/24/08
And yet, you assume...  elnyka | 07/24/08
hmmmm....  whitetigersx | 07/29/08
Assumption (of your own)  ZDNET_guest666 | 07/24/08
wrong  ysangkok@... | 07/24/08
RE: Irresponsible and evil  GreyGeek | 07/24/08
pad time...  whitetigersx | 07/29/08
I can't think of ANYONE who deserves to be...  flatliner | 07/23/08
Oh grow up cowboy! Ignorance is not bliss.  dunn@... | 07/24/08
No, but keeping the script kiddies & uneducated but resourceful terrorist.  invmgr@... | 07/24/08
Godwins Law, but now on terrorists?  alecco | 07/25/08
Publish just 2 days & the attacks are on. Maybe I was right, hmmm?  invmgr@... | 07/29/08
So What  KStads | 07/23/08
AGREED, and it gives you test code....  dunn@... | 07/24/08
true but,  whitetigersx | 07/29/08
RE: Attack code published for DNS flaw  jamalystic | 07/24/08
For those of you..  supercharlie | 07/24/08
Just plain dumb  Stan57 | 07/24/08
huh?  whitetigersx | 07/29/08
Held Responsible  Shayd | 07/24/08
I'm afraid you misunderstand, Shayd  JediMercer | 07/24/08
right...Fear Mongering  Shayd | 07/25/08
You're right...  whitetigersx | 07/29/08
There are losers everywhere.  lschw1 | 07/24/08
Attackers, watch your back.  Ngallendou | 07/24/08
Slight error in logic  ich1 | 07/24/08
RE: Attack code published for DNS flaw  mel@... | 07/25/08
What??  psychosmurf | 07/27/08
correct...  whitetigersx | 07/29/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

IT Solutions for 2010

  • Get cost-effective strategies and roadmaps on the most important issues facing IT leaders in 2010! Learn how to easily cut costs and deliver greater efficiency starting with your database, IT compliance management and data center. Visit the IT Leaders Dashboard. Visit the IT Leaders Dashboard.
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline