4 ms·
At least VUPEN restricts who they sell to. "Step Ahead" sounds like they've dropped even the pretense of being for pen testers.
by trotsky 15y ago
At least VUPEN restricts who they sell to. "Step Ahead" sounds like they've dropped even the pretense of being for pen testers.
- dsl 15y agoI think you mean Intevydis, "Step Ahead" is the name of the product. Immunity makes the framework all these exploit packs plug into and acts as the primary sales channel for them. They do a pretty good job of keeping the undesirables out, but like any other desirable software product copies do have a tendency to grow legs and follow employees home.
- trotsky 15y agoNo, I meant the product line - you don't get this bug in their "pro" version, only "step ahead" - step ahead of the vendors presumably. It seems hard to believe that private 0-days are legitimate pentesting apparatus - what are you testing in this case, whether your enterprise runs software that someone might find a bug in in the future? As far as I understand it canvas/Immunity is firmly in the offensive security market anyway, aren't they actively part of the scene that derides "killing bugs" aka reporting security bugs to software vendors (for any price)? I'm sure this bug hasn't been reported to Adobe, all they'd be doing is closing their marketing window.