OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Dailydave] Lame studies that people quote as fact that haveno basis in reality and still don't prove anything even if they did

From: H D Moore (hdm-daily-davedigitaloffense.net)
Date: Wed Feb 04 2004 - 21:43:59 CST


On Wednesday 04 February 2004 09:08 pm, you wrote:
> still you have not named one remote "shell popping" vulnerability in
> the default install.

True, I misread your statement, I was referring to a typical installation
instead of the out-of-the-box state. Most of the "shell popping" bugs are
in non-default services (uPnP, SNMP, etc). Some vendors shipped 98 with
these services enabled, but it doesn't really count as a default install.
There were a ton of services shipped with the default install but not
enabled, I am guessing these also don't apply for your comparison.

> yes, there are BSOD but they do not matter much for real hackers, only
> fame seeking win32 vuln researchers.

So Guninski is a fame-seeking win32 vuln researcher? :-) He posted his
ipv6 crash bug for obsd today...

Anyhow, didn't mean to start a debate, just thought of a handful of 98
bugs off-hand.

> ping!
> -noir

-HD