|
Re: Hmph: msg#00034security.dailydave
I'm not sure I see why we need a 3rd-party patch so urgently. The mitigation described by MS works and is fairly painless, so presumably you'd start with that if you are running DNS, and then wait for the patch from MS?
I agree that it was only a matter of time before hackers identified the flaw - either using the info on the ISC diary page or from MS's advisory. Perhaps saying that it was a stack BO made it a *little* easier to find, but that would be the obvious thing to start looking for in the first place.
Tucker. On 4/16/07, Dave Aitel <dave@xxxxxxxxxxxxxxx> wrote:
-----BEGIN PGP SIGNED MESSAGE----- _______________________________________________ Dailydave mailing list Dailydave@xxxxxxxxxxxxxxxxxxxxx http://lists.immunitysec.com/mailman/listinfo/dailydave |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | relro, aslr & stuff: 00034, Sebastian Krahmer |
|---|---|
| Next by Date: | Re: relro, aslr & stuff: 00034, Joel Eriksson |
| Previous by Thread: | Hmphi: 00034, Dave Aitel |
| Next by Thread: | relro, aslr & stuff: 00034, Sebastian Krahmer |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |