4 ms·
Marketing. Companies like rapid7 use that to say “only we detect this live threat, buy us fast!”.
by liquidpele 3y ago
Marketing. Companies like rapid7 use that to say “only we detect this live threat, buy us fast!”.
- c0pium 3y agoIt’s primarily marketing for sure, but the fig leaf is that the details allow targeted detections and mitigations based on the details of the bug. You can use the PoC code to test WAF rules for instance.
- gregoriol 3y agoSo why not inform vendor, release a statement like "found something big" without details, get the marketing from it, and provide the details 30 days after patch is made available. That way it hurts users less.
- ziddoap 3y ago>and provide the details 30 days after patch is made available.That way it hurts users less. The bad guys will figure out how to go about exploiting the vulnerability almost immediately after the patch releases, if they aren't already exploiting it. It makes 0 sense and protects 0 people to hold onto details after the patch is made available.
- gregoriol 3y agoThis is true for open-source but not as much for closed-source as in this case. Also, how does it ever help anyone to have the details released? It only helps the researchers for PR and bad actors, never the users who need to apply the patch (and often need some time to, one can't just upgrade something out of nowhere in less than 24 hours).
- ziddoap 3y ago>This is true for open-source but not as much for closed-source as in this case. It is just as applicable to closed-source as it is open-source. The people who are good at developing exploits are, unsurprisingly, good at reverse engineering and using disassemblers. It is generally trivial to figure out exactly what issues a patch is fixing if you are an experienced reverse engineer, and it's a short journey to developing an exploit once you have that knowledge. >Also, how does it ever help anyone to have the details released? Because the details will illuminate many potential indicators of compromise, which can be used throughout the defense stack (e.g. YARA rules, ASA rules, etc.)