[Dailydave] Holes, chips, dip.

Dave Aitel dave at immunityinc.com
Fri Jul 25 06:15:40 EDT 2008


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Weird coincidence with that Quantas flight today re: Dan Geer's email.

Also, has anyone looked into this bug? It's essentially something in the 
floating point instruction set of intel chips you can trigger from Java 
(or C# I assume) to escape the sandbox (write to memory, I assume).
http://www.infoworld.com/article/08/07/14/Researcher_to_demonstrate_attack_code_for_Intel_chips_1.html

The motto of the week is that you can't hint at bugs or people will just 
find them. Either full disclosure or no-disclosure wins, because there's 
no point doing anything else. :>

- -dave
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFIiafLtehAhL0gheoRAk3IAJ9YZ8fMaxLWCcoFD4RLAb89hONs4QCfabU6
W114Co0kGmJGAvvUqyS2RZc=
=KPkY
-----END PGP SIGNATURE-----



More information about the Dailydave mailing list