|
When it comes to security, public disclosure of vulnerabilities and working exploit code is now common. We look at why this can be both harmful and helpful to securing your systems.
Last month, I wrote about the DNS security issues, and I included examples of how to exploit it before the magazine went to print. Since then, a friend and I were discussing how exploitable the DNS issue actually was – I said it was relatively easy to exploit, and he thought that it would be difficult at best.
We both stuck to our guns until he said, “If you think it’s so easy, go write exploit code for it.” My reply was, “Why bother? Someone will write exploit code or a Metasploit module for it within a few days or weeks and release it publicly,” which they did.
|
| Related Articles | |
|---|---|
| DNS ATTACKS | The soft chewy center of the Internet |
| ApacheCon US video archive |
|---|
|
All about Apache in 19 talks Watch 19 talks from the ApacheCon US in New Orleans from the convenience of your home or office. Topics are: Scaling Apache 2.x in all dimensions, Securing Communications with your Apache HTTP Server, Scripting your Java Application with BSF 3.0 and much more. |
Comments