Re: SLFS book chapter proposals
Andrew Calkin <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Sun, Dec 21, 2003 at 03:52:44PM -0500, ashes wrote: > On December 21, 2003 02:50 pm, Archaic wrote: > > On Sat, Dec 20, 2003 at 07:13:40PM +0000, Ian Molton wrote: > > > I dont like the idea of sites showing how to exploit the vuln. you can > > > prove them without giving skiddies the tools. > > > > Perhaps, but this is open source, and I'd rather it be published than > > not. Besides, whether we link to it or not is irrelevant as the script > > kiddies can get their hands on it, regardless. > > Unlike security advisories or news stories, (S)LFS is a book. Its size, and > detail is unlimited. The scope of the SLFS can also be unlimited. Showing > proof and examples of exploits would increase awareness. Just as script > kiddies can use, modify, and distribute, so can the rest of us. We have to > take the bad with the good. Showing how exploits work will help encourage > better code in the future. I think its best not to link off to other docs, > real books dont do this. They should be rewritten with the SLFS perspective. > > I agree in part, but initially I think links to _good_ references should be used, with rewrites done when the prospective author(s) in the project have time. In this way, things can be made to start moving quickly, and much testing can begin amongst the team, before we get tied down with (improved) rewrites of theory that exist in some form at this point already. //Andrew -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page