This is an incredible resource for anyone looking into zeroday exploits and I'm happy to say that I helped with ithttp://www.rand.org/pubs/research_reports/RR1751.html …
-
-
Replying to @dguido
Attempts to score vulnerabilities for severity are disconnected from the reality of exploiting them.pic.twitter.com/Km7mgW2Kuh
2 replies 27 retweets 41 likes -
Replying to @dguido
Defensive efforts to patch vulnerabilities have little effect on exploits. They usually die from unrelated code churn.pic.twitter.com/cVZRZwrVzQ
3 replies 9 retweets 15 likes -
Replying to @dguido
Many eyes (and open source) DO NOT make all bugs shallow. Linux among the highest life expectancy for exploits.pic.twitter.com/ILOUTqoPVi
4 replies 55 retweets 65 likes -
Replying to @dguido
AGAIN: efforts to patch or disclose your way to killing exploits don't work (*cough* Project Zero). Most die from code refactors.pic.twitter.com/tXF5rFI98J
7 replies 38 retweets 43 likes -
Replying to @dguido
If an exploit does get rediscovered, it gets rediscovered quickly... or not really at all.pic.twitter.com/nf7GfZ1dAP
1 reply 13 retweets 18 likes -
Replying to @dguido
Exploit buyers overwhelmingly purchase in response to direct, operational needs.pic.twitter.com/UNGL8wnC0K
1 reply 9 retweets 8 likes -
Replying to @dguido
Crowdsourcing vulns is insufficient. Strategic guidance on architecture, mitigations is essential for good defense.pic.twitter.com/MqEnhZdPw0
2 replies 15 retweets 9 likes
"Offensively focused researchers employ different methods of finding bugs than defensively focused ones." Hire a red team!pic.twitter.com/E4VkYMXEnf
-
-
Replying to @dguido
Selecting the RIGHT vulnerability appears to be the most time consuming part of exploit development.pic.twitter.com/yZ63tjrCQ8
1 reply 6 retweets 8 likes -
Replying to @dguido
As an exploit developer, you're having a GREAT year if you ship 4 exploits.pic.twitter.com/iOKN5qpT53
1 reply 19 retweets 22 likes - 6 more replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.