Linked by Thom Holwerda on Fri 20th Mar 2009 13:51 UTC, submitted by google_ninja
Permalink for comment 354295
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
News
Linked by Thom Holwerda on 05/18/13 21:06 UTC
Linked by Thom Holwerda on 05/18/13 7:37 UTC
Linked by fran on 05/18/13 1:38 UTC
Linked by Thom Holwerda on 05/17/13 23:35 UTC, submitted by kragil
Linked by MOS6510 on 05/17/13 22:22 UTC
Linked by Thom Holwerda on 05/17/13 22:15 UTC, submitted by Tom
Linked by Thom Holwerda on 05/16/13 21:41 UTC
Linked by Thom Holwerda on 05/16/13 17:04 UTC
Linked by Thom Holwerda on 05/16/13 13:17 UTC
Linked by Thom Holwerda on 05/16/13 12:06 UTC
More News »
Sponsored Links



Member since:
2006-01-02
It's pretty costly to develop an exploit against a Vista flaw. From Immunity Inc:
http://www.immunitysec.com/downloads/ApologyofOdays.pdf
Page 37: From Bug to Reliable Exploit on Win2k - ~12 days
Page 38: SP2/2k3 - ~20 days
Page 39: Vista - ~40 days
If it takes that amount of time for an expert researcher who is known in the 'grey' community for coming up with exploits for difficult areas, then chances are good that the average pre-packaged vulnerability will be quite expensive and a lot of potentially purchasers will become discouraged.
Also if the learning curve for exploit writing is steep enough maybe people will stop looking so hard (who's going to spend that much of their life looking for something when few people ever succeed?).