7 ms·
Worse than that. Apparently,Tavis emailed the exploit to Symantec in a password protected zip file. He included the password in the body of the email. The email
by zabuni 10y ago
Worse than that. Apparently,Tavis emailed the exploit to Symantec in a password protected zip file. He included the password in the body of the email. The email server, running Symantec, grabbed the password out of the email, decrypted the zip file, and upon reading the exploit code, crashed itself.
- ceejayoz 10y agoThat's a hell of a proof-of-concept.
- CiPHPerCoder 10y agoIt wasn't intentional. This was alluded to in Tavis's previous exploit. But that being said, it's hilarious.
- mdadm 10y agoSeriously? That's incredible. I'm not sure if I should be impressed that doing so worked, or saddened by the fact that it ACTUALLY WORKED...
- MawNicker 10y agoIt's hilariously ironic. They're in the business of scanning things which smart people want them not to. How does someone send them something they really shouldn't scan?
- cypherpunks01 10y agoI very much started reading your post as a comedic sci-fi ending to the story.. but now I am actually not sure. It would be quite creative to think of that scenario! Did this happen?
- pfg 10y agoI'm afraid this did actually happen[1]. [1]: https://bugs.chromium.org/p/project-zero/issues/detail?id=820#c1 https://bugs.chromium.org/p/project-zero/issues/detail?id=82...
- ComodoHacker 10y agoThis is just an assumption
- amenod 10y agoI do not see any indication in the link you posted. Am I missing something?
- pfg 10y ago> I think Symantec's mail server guessed the password "infected" and crashed (this password is commonly used among antivirus vendors to exchange samples), because they asked if they had missed a report I sent.
- deleted 10y ago[deleted]
- jkn 10y agoAt least they eat their own dog food.
- monkeyhill 10y agoAt the end of the day, we all pivot back to our own solutions when it appears we're almost out of runway.
- deleted 10y ago[deleted]
- joosters 10y agoNice to see that even security researchers can't be bothered to PGP encrypt their messages then.
- toyg 10y agoWhy should they? Signing, maybe; encrypting, superfluous and risky in this context (if the other party won't accept or read encrypted mail).
- joosters 10y agoPerhaps because they are discussing critical system vulnerabilities, some of which would be disastrous if they got into the 'wrong' hands before they were patched? And, from Symantec's own page: Symantec strongly recommends using encrypted email for reporting vulnerability information
- deleted 10y ago[deleted]