On Fri, 18 Jul 2008, David Schwartz wrote:haven't you ever heard of script-kiddies? they are by far the majority of attacks on systems but do not have the expertise to create exploits. it takes someone else writing the exploit for them and packaging it to make them a threat. in the meantime there's a chance for the fix to get propogated out to a released version and for people to upgrade their systems. providing exploit code along with the bugfix means that the script kiddies have the exploit immediatly, but the fix isn't in any released version (not even a -rc or daily -git snapshot) this depends on how you define threat. how many people run exploits against their production systems to 'see if they are fixed', very few, and those only on strict schedules with lots of adnvance notice and other safeguards. David Lang --
| Stephen Smalley | Re: [AppArmor 39/45] AppArmor: Profile loading and manipulation, pathname matching |
| Tarkan Erimer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Jan Engelhardt | intel iommu (Re: -mm merge plans for 2.6.23) |
| Greg Kroah-Hartman | [PATCH 005/196] Chinese: add translation of SubmittingDrivers |
git: | |
| David Fenyes | sigsetmask()? (LINUX) |
| Stephen Tweedie | Unmounting root (no kidding!) [was: Some Linux problems---solved] |
| Les Andrzejewski | X386/WD90C31/SUMSUNG SYNC MASTER 4 |
| Doug Evans | Re: Stabilizing Linux |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| Linus Torvalds | Re: [GIT]: Networking |
| Jarek Poplawski | [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Herbert Xu | Re: [PATCH] myr10ge: again fix lro_gen_skb() alignment |
