Why Didn’t the “Good Guys” Find the WMF Vulnerability?

While I wouldn’t call it a new class of vulnerability, per se, it certainly exhibits some unique characteristics to make it more research-worthy than finding buffer overflows.

3 comments for “Why Didn’t the “Good Guys” Find the WMF Vulnerability?

  1. January 12, 2006 at 10:21 am

    What makes you think they didn’t?

    Good guy =/= always discloses stuff…

  2. January 12, 2006 at 10:23 am

    Here is another simultaneous discovery story for you: http://lists.immunitysec.com/pipermail/dailydave/2006-January/002814.html

  3. Pete
    January 12, 2006 at 1:04 pm

    @Anton -

    “What makes you think they didn’t?”

    Because Microsoft didn’t know about it. (They’re not good if they don’t tell the vendor. You’re right, though, they don’t have to tell the world).

    Pete

Comments are closed.