Authors Public Collections Topics My Collections

Quotes by Michael Sutton

“I would certainly recommend that users implement the vendor workarounds until a patch is made available, ... We feel that exploit code can and will be created.”

“I would certainly recommend that users implement the vendor workarounds until a patch is made available. We feel that exploit code can and will be created.”

“It was definitely a surprise to see Ciscos reaction. I dont think thats the best approach. I do feel that it is happening less and that vendors are realizing that we dont want to work against them, but with them.”

“Ocean Champions has the potential to be one of the most transformative things weve ever done in the whole conservation movement.”

“Orders are slow right now.”

“The vulnerability still exists in Internet Explorer in that its very lenient in how it pulls CSS, but right now nobody is publishing a way that it can be leveraged to do something useful. Thats not to say that somebody wont find a way. Im sure somebody will come up with a creative way to leverage it to do something evil.”

“There is some irony there.”

“This is relatively easy to exploit. It takes some degree of social engineering -- the attacker would have to draw people to a malicious Web site -- but after that, theres no further intervention required. An attacker could leverage this to write to a file on the hard drive. And once you can write to a persons machine, you have full control.”

“Theres always code reuse in development, which is a good thing. No one writes an entire application from scratch. But if youre using someone elses code, youre relying on the security of that code. Developers need to apply the same level of security testing to those shared pieces as they do to their own code.”

“Patching is very urgent, ... We expect public exploit code to become available, especially for the MSDTC issue.”