OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
RE: [Full-disclosure] MSIE (mshtml.dll) OBJECT tag vulnerability

From: Michal Zalewski (lcamtufdione.ids.pl)
Date: Thu Apr 27 2006 - 07:57:19 CDT


On Thu, 27 Apr 2006, Larry Seltzer wrote:

> More on this in my column later this morning at
> http://security.eweek.com/

  "Just who does he think he is? [...] Zalewski may think he's some sort
  of hero disclosing this information, but his is the act of a vandal. If
  it turns out that the bug is exploitable and abused before it's patched,
  then perhaps he'll be proud to be remembered for that."

Ho boy. Yup. Now that you foiled that plan, at least I can be proud of
being featured in your op-ed as an egomaniac bent on hurting people by
providing them with information. That's almost as good.

/mz

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/