funsec mailing list archives

RE: Get your computer viruses here!


From: Drsolly <drsollyp () drsolly com>
Date: Thu, 29 Dec 2005 18:28:05 +0000 (GMT)

On Thu, 29 Dec 2005, C wrote:

On 12/29/05, Drsolly <drsollyp () drsolly com> wrote:

I do, however, have a choice in who I send malware to, and I *should* be
held responsible for distributing it with care.


Let me make a distinction.  First of all OC is not "sending" malware to
anyone.  It is offered as a public service for people to download if they
wish.

Yes, I know how HTTP works. 

If someone launches the malware against a network that is a serious
problem.  I would agree that is unethical.
 
But if Blackhat McNasty signs up to your web site and downloads the 
malware that he then launches against a network, is it your contention 
that you didn't contrinbute to the problem? 
 
The malware is being provided in a manner for research only.  We saw there

No. It's being provided, full stop. You're making no effort whatsoever to 
filter out people who are malicious.

was a problem in the vetting system that was currently in place.  Until
there is an industry-wide method for anyone to be vetted 

There already is such a method.

as a "malware
analyst" the free and open model must exist.
 
So the free and open model isn't necessary.

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: