Dailydave mailing list archives

Re: Some Sums


From: "Paul Melson" <pmelson () gmail com>
Date: Mon, 12 Feb 2007 11:09:33 -0500

2. A lot of people are "finding" things simply by being the first to aim
someone else's fuzzer at them. 
I'm not sure what this implies, but it implies something.

Ooh, maybe it implies that the art of finding software vulnerabilities is
ready for some big consultancy to turn it into a canned 2-week deliverable.
Experienced coders will be replaced by a couple of CSA's with Spike and
Peach and only 3 semesters of C++ between them.  

Perhaps eventually it will get to a point where Qualys builds a product
where you upload your .MSI file to a VM and they just e-mail you a report.

Or maybe it just means that as fuzzers get better, KF will have to announce
a QOAB or a YOAB.  :-)

PaulM


_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: