[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [Full-Disclosure] THCIISSLame exploit



>THC is a hacker group, not a cracker group.

Publishing root exploit source code is free speech and is protected.

Some countries don't have free speech, in fact most countries don't have the same laws, so you should've said "free speech is protected in XYZ"



Publishing the binary is VX-ing and is criminal. That is very clear.

Again, you assume this is illegal in every country. This is the Internet, there are no laws here. ;)


To share knowledge with security researchers does not require
releasing binary executables, professional testers can compile the
source code for themselves.

Not everyone has a C/C++ compiler. Even if you do have a C/C++ compiler, you may have to port the code to your OS which takes time. If you also compile the exploit, everyone can test it. You assume a script kiddie can't compile an exploit and that the script kidde can't use any of the exploits sent to this list if it's only in source form. Nice protection, but it doesn't work.


Avoid releasing binaries and you will not have problems with the authorities.

I assume you meant to say "Avoid releasing EXPLOIT binaries ..."


_________________________________________________________________
FREE pop-up blocking with the new MSN Toolbar ? get it now! http://toolbar.msn.com/go/onm00200415ave/direct/01/


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html