defining 0day
Date: Tue, 25 Sep 2007 14:02:27 -0500 (CDT)
From: Gadi Evron <ge@linuxbox.org.>
To: "Thor (Hammer of God)" <thor@hammerofgod.com.>
Subject: defining 0day
In-Reply-To: <F9C0B32C4FFE7147BD0FF6A40BE806E701ABEE@Hammer_Exchange.hammerofgod.com.>
Message-ID: <Pine.LNX.4.62.0709251359490.25733@linuxbox.org.>
References: <6905b1570709200621l2424978cr85de6a4c6939c283@mail.gmail.com.>
<Pine.LNX.4.62.0709201027590.8741@linuxbox.org.> <46F2FF36.100@novell.com.>
<46F5FACF.9010807@novell.com.> <20070923235235.GH41180@demeter.hydra.>
<Pine.GSO.4.60.0709241550120.27986@sploit.scriptkiddie.org.>
<64CF0185-2BDE-40D8-9BDC-9E66153186E1@e18.physik.tu-muenchen.de.>
<F9C0B32C4FFE7147BD0FF6A40BE806E701ABEE@Hammer_Exchange.hammerofgod.com.>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-1.7.5 (linuxbox.org [127.0.0.1]); Tue, 25 Sep 2007 14:02:29 -0500 (CDT)
X-Virus-Scanned: antivirus-gw at tyumen.ru
On Tue, 25 Sep 2007, Thor (Hammer of God) wrote:
> For the record, the original term "O-Day" was coined by a dyslexic
> security engineer who listened to too much Harry Belafonte while working
> all night on a drink of rum. It's true. Really.
>
> t
Okay. I think we exhausted the different views, and maybe we are now able
to come to a conlusion on what we WANT 0day to mean.
What do you, as professional, believe 0day should mean, regardless of
previous definitions?
Obviously, the term has become charged in the past couple of years with
the targeted office vulnerabilities attacks, WMF, ANI, etc.
We require a term to address these, just as much as we do "unpatched
vulnerability" or "fully disclosed vulnerability".
What other such descriptions should we consider before proceeding?
non-disclosure?
Gadi.