Tag: Vulnerability Disclosure
-
Vendor Confidence
[This was originally published on the OSVDB blog.] Lance James of Secure Science Corporation posted an advisory detailing a serious flaw in the Fedex/Kinkos ExpressPay smart card payment system. A knowledgeable attacker with relatively minor resources can abuse the system to defraud the company. In response to the advisory, Fedex/Kinkos replied to them saying: “Our…
-
State of vulnerability research?
[This was originally published on the OSVDB blog.] Steve Christey of CVE has posted to several lists asking What is the state of vulnerability research? Before you dismiss the question, give it serious thought for a few minutes. Have any ideas, opinions or concerns about where vuln research is heading? Where it should be? Drop…
-
For Journalists Covering Oracle…
[This was originally published on the OSVDB blog.] 2004-08-04: 34 flaws found in Oracle database software2004-09-03: US gov and sec firms warn of critical Oracle flaws2004-10-15: Oracle Warns of Critical Exploits2005-01-20: Oracle Patch Fixes 23 ‘Critical’ Vulnerabilities2005-10-19: Oracle fixes bugs with mega patch2006-01-18: Oracle fixes pile of bugs In the interest of helping journalists cover…
-
PHP-CHECKER
[This was originally posted to the OSVDB blog.] Yichen Xie and other Stanford researchers posted to bugtraq announcing “99 potential security vulnerabilities”, all SQL injections. Five issues/comments/questions come to mind: 1. This sounds impressive, but even by OSVDB’s level of abstraction (significantly higher than other VDBs), this is far from 99 vulnerabilities. Looking at the…
-
Selling Vulnerabilities: Going Once…
[This was originally published on the OSVDB blog.] A couple days ago, “fearwall” created an eBay listing for a “Brand new Microsoft Excel Vulnerability”. I have mirrored a screenshot in case the listing is removed, which I expect it to be. One has to wonder if companies like iDefense or Tipping Point will bid, since…
-
Perl Format Strings
[This was originally published on the OSVDB blog.] Dyad Security announced a new vulnerability in the Webmin miniserv.pl web server component. The perl is vulnerable to a format string bug, which is mostly unseen in perl and quite common in C programs. The post calls this a “a new class of exploitable (remote code) perl…
-
Security Advisories, Mail Lists, and You
[This was originally published on the OSVDB blog.] When a security researcher finds a vulnerability, they may choose to release the details in a formal advisory. The different between a random post to a mail list and an advisory typically involves the level of detail and the amount of peripheral information to the vulnerability. This…
-
Disclosure or Blatant Advertising?
[This was originally published on the OSVDB blog and re-published on the Sydney Morning Herald.] Security advisories are a form of advertising. First and foremost, they are used to promote the technical capability of a security company and showcase the talent. If a researcher or company was completely altruistic, they would not release an advisory…
-
Advisory Archives 102 (why Mandriva hates VDBs)
[This was originally posted on the OSVDB blog.] I recently made a post titled Mail List Archives 101 (or why SF hates VDBs) commenting about the restructure of the SecurityFocus mail list archive. In short, it’s a bad thing. Unfortunately for many people, especially vulnerability databases, this is happening more and more, on various sites.…
-
Vulnerability One Trick Pony?
[This was originally published on the OSVDB blog.] I know the title of this may seem to be a slight on the researches I will use as examples, but that is not the case at all. Some people in the security community have a perception that some vulnerability researchers are so-called “one trick ponies“, meaning…