Re: Re: Exploit-based signature is dead, or not?
"tanyoo10" <[email protected]>
| Newsgroups | gmane.comp.security.ids |
|---|---|
| Message-ID | <[email protected]> |
Hi Sergio 'shadown' Alvarez, >just in case you didn't realize...if you have the exploit to generate >the signature, you already know what the vulnerability is. Exploit-based signatures are usually generated by finding the artifacts in a number of exploit samples. Thus, having exploit-based signature does't mean that we already know the vulnerability. cheers, Yong