RE: [stable] Linux 2.6.25.10

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: David Schwartz
Date: Friday, July 18, 2008 - 6:51 pm

David Lang wrote:



Nobody is saying you should package the exploit. If they need someone else
to package it, they'll still need that. So the question is not if this will
deter script kiddies but whether it will deter the people who package
exploits for them. And from experience, I can tell you that answer is no.
Manys attacks that were believed too difficult for the script kiddies to do
were packaged by people who had the expertise and then used by script
kiddies.


The alternative is that the fix gets released but not implemented.



I can tell you how many run exploits against their production systems when
they don't know the exploits exist -- zero. It takes, at a minimum, the
knowledge that an exploit is possible. In the cases being discussed, even
this was withheld.

Fixes will not be widely deployed on a timely basis unless, at an absolute
minimum, it is known that there is an exploitable bug that has been fixed.

DS


--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Linux 2.6.25.10, Greg KH, (Wed Jul 2, 8:58 pm)
Re: Linux 2.6.25.10, Greg KH, (Wed Jul 2, 8:58 pm)
Re: Linux 2.6.25.10, Bart Van Assche, (Thu Jul 3, 10:08 am)
Re: Linux 2.6.25.10, Greg KH, (Thu Jul 3, 10:29 am)
Re: Linux 2.6.25.10, Greg KH, (Thu Jul 3, 11:57 am)
Re: Linux 2.6.25.10, pageexec, (Thu Jul 3, 12:31 pm)
Re: Linux 2.6.25.10, Bart Van Assche, (Sat Jul 5, 12:54 am)
Re: Linux 2.6.25.10, Greg KH, (Mon Jul 7, 9:12 pm)
Re: [stable] Linux 2.6.25.10, Greg KH, (Mon Jul 14, 5:04 am)
Re: [stable] Linux 2.6.25.10, pageexec, (Mon Jul 14, 7:14 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Mon Jul 14, 7:27 pm)
Re: [stable] Linux 2.6.25.10, pageexec, (Tue Jul 15, 8:31 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 9:07 am)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 9:13 am)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Tue Jul 15, 11:33 am)
Re: [stable] Linux 2.6.25.10, pageexec, (Tue Jul 15, 12:03 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 12:16 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 1:15 pm)
Re: [stable] Linux 2.6.25.10, pageexec, (Tue Jul 15, 1:28 pm)
Re: [stable] Linux 2.6.25.10, Greg KH, (Tue Jul 15, 3:39 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 3:47 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 4:08 pm)
Re: [stable] Linux 2.6.25.10, pageexec, (Tue Jul 15, 4:09 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 4:21 pm)
Re: [stable] Linux 2.6.25.10, pageexec, (Tue Jul 15, 4:22 pm)
Re: [stable] Linux 2.6.25.10, pageexec, (Tue Jul 15, 4:26 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 4:26 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 4:34 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 4:35 pm)
Re: [stable] Linux 2.6.25.10, Aidan Thornton, (Thu Jul 17, 2:08 pm)
RE: [stable] Linux 2.6.25.10, David Schwartz, (Fri Jul 18, 5:47 pm)
RE: [stable] Linux 2.6.25.10, david, (Fri Jul 18, 6:01 pm)
RE: [stable] Linux 2.6.25.10, David Schwartz, (Fri Jul 18, 6:51 pm)
Re: [stable] Linux 2.6.25.10, Willy Tarreau, (Fri Jul 18, 10:41 pm)
Re: [stable] Linux 2.6.25.10, Bernd Eckenfels, (Sat Jul 19, 6:13 pm)