Re: SLFS book chapter proposals
Pascal J.Bourguignon <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | InformatiMago. |
| Message-ID | <[email protected]> |
Ian Molton writes: > On Sat, 20 Dec 2003 09:32:32 -0500 > Robert Day <[email protected]> wrote: > > > > > > IIRC, examples are shown and publicly available on sites dedicated > > > to security. I don't have the URLs availabe ATM, but they could be > > > included in the book to provide that info. IIRC, one of the standard > > > procedures on these sites requires proof of the weakness, including > > > code that exploits the vulnerability. > > I dont like the idea of sites showing how to exploit the vuln. you can > prove them without giving skiddies the tools. You could prove all you wanted, corporations were not moved. But once their customers get hit by skiddies, and then make their lawyers move against the software providers, then they are moved to correct their bugs. Of course, free software development does not follow the same rules, but exploit publication is a good thing to improve closed software. (That's perhaps two more reasons against publishing... :-) -- __Pascal_Bourguignon__ . * * . * .* . http://www.informatimago.com/ . * . .* There is no worse tyranny than to force * . . /\ ( . * a man to pay for what he does not . . / .\ . * . want merely because you think it .*. / * \ . . would be good for him. -- Robert Heinlein . /* o \ . http://www.theadvocates.org/ * '''||''' . SCO Spam-magnet: [email protected] ****************** -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page