<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>How is this stuff found? in </title>
<link>http://www.dslreports.com/forum/r17524422</link>
<description></description>
<language>en</language>
<pubDate>Wed, 02 Dec 2009 14:21:35 EDT</pubDate>
<lastBuildDate>Wed, 02 Dec 2009 14:21:35 EDT</lastBuildDate>

<item>
<title>Re: How is this stuff found?</title>
<link>http://www.dslreports.com/forum/remark,17526678</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : For buffer overflows, you can just try dumping a long, long string of data into every function that takes strings of data and see which ones crash.<br><br>If a long, long string of data causes your OS to crash (in one way or another, not necessarily requiring a complete reboot), then you've overwritten something and maybe you can use this to your advantage to overwrite executable code.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17526678</guid>
<pubDate>Tue, 26 Dec 2006 19:49:40 EDT</pubDate>
</item>

<item>
<title>Re: How is this stuff found?</title>
<link>http://www.dslreports.com/forum/remark,17525607</link>
<description><![CDATA[<A HREF="/useremail/u/687617"><b>severach</b></A> : Black hats harm everybody by destroying stuff. The white hats either do something that is unimportant to you or something that is highly desirable to you but highly undesirable to Microsoft. For example, if a white hat found out a way to permanently disable the signed driver protection in Vista, that would be wonderful for everyone in the world except for Microsoft who's sole purpose for that feature is to prevent you and me from modifying the system to our advantage. Noone wants that except for Microsoft.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17525607</guid>
<pubDate>Tue, 26 Dec 2006 14:17:52 EDT</pubDate>
</item>

<item>
<title>Re: How is this stuff found?</title>
<link>http://www.dslreports.com/forum/remark,17525540</link>
<description><![CDATA[<A HREF="/useremail/u/290436"><b>72276539</b></A> : <div class="bquote"><SMALL>said by  John_W <A HREF="/useremail/u/154241"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>  MS has had a habit of ignoring white hat findings, or at best putting off, where other software companies, like mozilla, who who get their patches right out there as soon as they can.<br> </DIV>It's a hell of a lot fuckin easier to edit code on a browser then an entire OS. How bout comparing apples to apples instead of apples to porcupines. <br><br>PS- Answer the OP's question while you are at it.<br><SMALL>--<br>RIP Dimebag- August 20, 1966 to December 8th, 2004.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17525540</guid>
<pubDate>Tue, 26 Dec 2006 14:03:20 EDT</pubDate>
</item>

<item>
<title>Re: How is this stuff found?</title>
<link>http://www.dslreports.com/forum/remark,17525142</link>
<description><![CDATA[<A HREF="/useremail/u/1266681"><b>rdmiller</b></A> : didn't answer the question!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17525142</guid>
<pubDate>Tue, 26 Dec 2006 12:47:06 EDT</pubDate>
</item>

<item>
<title>Re: How is this stuff found?</title>
<link>http://www.dslreports.com/forum/remark,17524464</link>
<description><![CDATA[<A HREF="/useremail/u/154241"><b>John_W</b></A> : It's the black hats we have to worry about.<br><br>It's the white hats MS has to worry about.  It's how quickly the software companies respond to the white hat vulnerability discoveries that concern us.<br><br>Almost all, if not all, software has some sort of exploitable code in it.  It is just how fast those companies fix the problem that makes the difference between a good and bad company.   MS has had a habit of ignoring white hat findings, or at best putting off, where other software companies, like mozilla, who who get their patches right out there as soon as they can.<br><SMALL>--<br>Chef says to put a cucumber down my pants for good luck.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17524464</guid>
<pubDate>Tue, 26 Dec 2006 10:11:42 EDT</pubDate>
</item>

<item>
<title>How is this stuff found?</title>
<link>http://www.dslreports.com/forum/remark,17524422</link>
<description><![CDATA[<A HREF="/useremail/u/332694"><b>bleearg13</b></A> : Reading about one of the vulnerabilities, I'm interested to know <STRONG>how</STRONG> these vulnerabilities are discovered.  There are obviously hackers/crackers and researchers alike that spend every waking hour trying to identify vulnerabilities, but exactly how is it done?  Most specifically, this exploit regarding the "MessageBox" function:<br><br>&raquo;<A HREF="http://www.darkreading.com/document.asp?doc_id=113414" >www.darkreading.com/document.asp&middot;&middot;&middot;d=113414</A><br><br>How on earth is this found?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17524422</guid>
<pubDate>Tue, 26 Dec 2006 09:59:19 EDT</pubDate>
</item>

</channel>
</rss>
