4 ms·
In cases where a small vulnerability is successfully turned into a larger vulnerability, everyone wins, right? Considering that there is “more than one way to
by dumpsterdiver 3y ago
In cases where a small vulnerability is successfully turned into a larger vulnerability, everyone wins, right?
Considering that there is “more than one way to skin a cat”, it is not a given that vulnerabilities further along the chain will be resolved by closing the initial vector.
When a chain of vulnerabilities is reported it might become clear that not only does the initial attack vector need to be closed, but additional work needs to be done in other areas because there are other ways to reach that code which was called further along the attack chain.
- Aurornis 3y ago> In cases where a small vulnerability is successfully turned into a larger vulnerability, everyone wins, right? Nope! The two vulnerabilities are usually one and the same. The person is just trying to find a clever way to access additional data to make their payout larger. From the customer perspective, getting the initial vulnerability fixed ASAP is the best outcome. When they start delaying things to explore creative ways to make their payout larger, everything goes unfixed longer.