Checking vulnerabilities without access to the source code?

Reply

Join Date: Oct 2006
Posts: 174
Reputation: tech291083 is an unknown quantity at this point 
Solved Threads: 0
tech291083 tech291083 is offline Offline
Junior Poster

Checking vulnerabilities without access to the source code?

 
0
  #1
Nov 30th, 2006
hi,

we often hear that a certain software product has security holes as claimed by research firms/ hackers and security solutions vendors. i just came across one article as follows,
about sql server and oracle rdbms.

http://www.theinquirer.net/default.aspx?article=36000

as far as i understand, in order to know in what sense a software is having a security issue/hole/vulnerability, one needs to have access to the source code of the product in question. but many a time it looks like that source code is not made available to these companies/hackers etc and still they report the problems. how does this work? thanks.
Reply With Quote Quick reply to this message  
Join Date: May 2006
Posts: 1,812
Reputation: ithelp is a name known to all ithelp is a name known to all ithelp is a name known to all ithelp is a name known to all ithelp is a name known to all ithelp is a name known to all 
Solved Threads: 117
ithelp's Avatar
ithelp ithelp is offline Offline
Posting Virtuoso

Re: Checking vulnerabilities without access to the source code?

 
0
  #2
Feb 28th, 2007
It is not required, you can learn a lot from windows internals books,oracle handbook, you already have some opensource like postgresql/linux to play with and list down what all are the main bugs, try to attack a simmilar database/os using the knowledge you have gained
Reply With Quote Quick reply to this message  
Join Date: Oct 2006
Posts: 174
Reputation: tech291083 is an unknown quantity at this point 
Solved Threads: 0
tech291083 tech291083 is offline Offline
Junior Poster

Re: Checking vulnerabilities without access to the source code?

 
0
  #3
Mar 1st, 2007
Originally Posted by ithelp View Post
It is not required, you can learn a lot from windows internals books,oracle handbook, you already have some opensource like postgresql/linux to play with and list down what all are the main bugs, try to attack a simmilar database/os using the knowledge you have gained
Brilliant, cheers mate. Appreciated.
Reply With Quote Quick reply to this message  
Join Date: Nov 2006
Posts: 23
Reputation: Day Brown is an unknown quantity at this point 
Solved Threads: 0
Day Brown Day Brown is offline Offline
Newbie Poster

Re: Checking vulnerabilities without access to the source code?

 
0
  #4
Apr 6th, 2007
Part of the problem Microsoft has, is that programmers are not fools. Back in the 80's M$ stole software sure that they had enough lawyers to keep a programmer in court forever. SO- programmers began inserting "back doors" into their code, strings of assy bytes, that if called could call external subroutines you know as viruses.

So, Microsoft has stolen the code along with the back doors, and at this point, has no idea how much it has stolen.
Reply With Quote Quick reply to this message  
Join Date: May 2007
Posts: 38
Reputation: matale is an unknown quantity at this point 
Solved Threads: 1
matale matale is offline Offline
Light Poster

Re: Checking vulnerabilities without access to the source code?

 
0
  #5
Sep 21st, 2007
Originally Posted by Day Brown View Post
Part of the problem Microsoft has, is that programmers are not fools. Back in the 80's M$ stole software sure that they had enough lawyers to keep a programmer in court forever. SO- programmers began inserting "back doors" into their code, strings of assy bytes, that if called could call external subroutines you know as viruses.

So, Microsoft has stolen the code along with the back doors, and at this point, has no idea how much it has stolen.
My current Project www.footystat.com
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:


Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC