lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Mon, 5 May 2008 18:03:52 +0100 From: n3td3v <xploitable@...il.com> To: full-disclosure@...ts.grok.org.uk Subject: Re: HD Moore On Mon, May 5, 2008 at 4:20 PM, <Valdis.Kletnieks@...edu> wrote: > On Sun, 04 May 2008 16:27:49 BST, n3td3v said: > > On Fri, May 2, 2008 at 9:32 AM, Nate McFeters <nate.mcfeters@...il.com> wrote: > > > Oh that... Yeah, shame on hd... Maybe he was busy updating metasploit > > > so that real researchers have a great vulnerability development > > > framework, or something else that provided some worth to people. > > > > Maybe he was busy updating Metasploit so that script kids have a great > > vulnerability development framework. > > > > He should stop providing them with a great vulnerability development framework. > > There's 2 really great uses for metasploit for white hat security guys: > > 1) When you're handed a /16 or two during a pen test, and need a quick way > to poke a whole bunch of machines for a vulnerability, it's hard to roll-your-own > exploit tester as fast as you can chinese-menu one in metasploit. > > 2) It's a *great* tool for impressing on a PHB just how easy it is to launch > an exploit for something at one of the unsecured systems he's responsible for. I stand by everything i've said in this thread and said it to HD Moore on IRC months ago, including government conspiracies. All the best, n3td3v _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists