OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
RE: defining 0day

From: David Gillett (gillettdavidfhda.edu)
Date: Tue Sep 25 2007 - 16:20:52 CDT


> What do you, as professional, believe 0day should mean,
> regardless of previous definitions?

  I think there is some slight residual usefulness to designating
vulnerabilities whose first public disclosure results from
discovery/analysis of an active exploit already "in the wild". ("0 days"
thus being the elapsed time from public disclosure of the vulnerability to
appearance of a live threat exploiting it, a characteristic which an unknown
vulnerability may only aspire to, and a patched one may never live down.)

David Gillett