Linked by Thom Holwerda on Thu 26th Mar 2009 20:51 UTC
Thread beginning with comment 355319
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.





Member since:
2006-02-09
Phuhck Charlie Miller. He sits on a vulnerability for a year as a sure thing so he could win yet another prize and show off his '1337 sKiLs'. So he basically sat around on his ass for a year and did NOTHING.
"In neither case did I get root/admin access. That would have required additional vulnerabilities. However, just running as the user is still very bad,"
So you get into a box as a 'regular' unprivileged user and you expect to accomplish just what? How would you 'get root' on the box after sitting around for a year thinking that you had it all sewn up and you couldn't pull another vuln out of your hugely inflated ego. Maybe you're not as 'kEwL' as you think, Charlie. The only things that his 'uber-sploit' shows is that it's a bad idea for any software that connects to the 'intarwebs' to be integrated with the OS and that security 'researchers' like Charlie are egotistical mercenaries. Period.