4 ms·
Trustwave was the outside party running the penetration test. 0-days are commonly used by pentesters, and are available for purchase by subscription as well as
by trotsky 14y ago
Trustwave was the outside party running the penetration test. 0-days are commonly used by pentesters, and are available for purchase by subscription as well as one offs that are made available via mailing lists etc.
For example: https://www.immunityinc.com/canvas-cep.shtml https://www.immunityinc.com/canvas-cep.shtml
This is standard practice for the industry and quite common. But do note that not all 0-days are created equal: a 0-day that effects 1000 users is 1000x the significance of one that effects only one user (with some notable exceptions). Also realize that 0-day is often used misleadingly - anything that was first used in the wild is a 0-day, even if that event was months ago, the vendor has been informed, and crucially - even if a patch has been issued by the vendor. Pentest firms often oversell their "0-days" in an effort to appear more advanced to their clients.