Enabling Secure Business Operations

A month of browser bugs

H.D. Moore, author of Metasploit, has decided that enough time has passed since he informed the various browser vendors about serious bugs, and has launched the month of browser bugs blog. “The vendors have been notified and the time has come to start publishing the results,” Moore said in a blog posting. “This information is being published to create awareness about the types of bugs that plague modern browsers, and to demonstrate the techniques I used to discover them.”

This blog contains one bug per day including exploit code. This newsfactor story has some details.

“The fact remains that the browsers have too many vulnerabilities and we are all better off if Moore exposes them before the criminals exploit them,” said Avivah Litan, an analyst at Gartner.

Are we really better off with these exploits now available to script kiddies? Or, do you agree with Andrew Jacquith, a Yankee Group analyst:

“I don’t know what H.D.’s process was—but it looks like the details are being made public before the vendors can release corresponding patches. So I’d say, ‘No, it’s not responsible disclosure.’”

One Response to “A month of browser bugs”

  1. Anil Says:

    I don’t think that this is responsible disclosure.

    It is like saying,

    “I’m fed up with so many cars being stolen ever year (unhappy with poor browser security).

    So, I’m just going to announce how to break in to cars. Honda – well, they have a latch mechanism so…(making people “aware.”)

    Oh yea, and I’m going to hand out crow bars, lock picks, and whatever else you need to break in (exploit code).”

    All in the hopes that car manufacturers start making cars harder to break into. Hmmm…doubt that will happen as a result of creating more criminals. People will still buy cars, just as people will still use browsers with swiss cheese security. The only people who care about vulnerability disclosures and exploit code are security “people” and hackers both good and bad.

    Eventually security will get better, but I bet more cars will be stolen in the mean time.

    So, does giving Lex Luthor kryptonite make Superman stronger? I don’t know either, but it sure makes for a better movie…

Leave a Reply