4 ms·
Browser exploit packs absolutely care about version numbers. It's how they determine what if any exploits to push to a client. Nessus, on the other hand, will n
by trotsky 15y ago
Browser exploit packs absolutely care about version numbers. It's how they determine what if any exploits to push to a client. Nessus, on the other hand, will never look at a user-agent string. So while you're probably correct for one class of threats and targets (targeted and enterprise servers) I wouldn't agree at all that the world is as black and white as you're claiming.
- tptacek 15y agoAre we talking about modifying your browser binary to defeat memory disclosure exploits? I didn't think we were talking about that.
- trotsky 15y agoIt certainly seems in scope to me if we're talking about version identifiers, and it (along with several other examples) are clear situations where changing an identifier string could definitely lead to an automated attack that would succeed never being tried. And you don't need to modify any binaries: The easiest way to change something like that is in a transparent proxy, but ie also supports changing via the registry, opera and firefox via about:config, etc.
- tptacek 15y agoWhat's an example of a serverside vulnerability that cares about version banners?
- trotsky 15y agoWhat vulnerability depends on a specific version banner? Surely you're not insisting that the actual bug be predicated on the fact that one version prints instead of another. A server intrusion work flow that involves a version banner? Saint on /24 -> choose exploit & target based on results. I understand you've said either this isn't worth the tradeoffs or 0days aren't getting mass exploited this way, but it is hard to believe you really disagree that intrusions happen in this fashion.
- tptacek 15y agoThat's how security consultants break into machines. If you're arguing that someone with a very recent SSH remote is going to use Saint to scope out a target, no; doubt it.