Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And the educational factor of "it can be done" is essentially all the justification needed to supply PoC with bug reports.

I mean, take:

http://seclists.org/oss-sec/2017/q1/675

"I am able to crash a RHEL7'ish system with the above PoC quickly."

So, someone takes down some critical system running RHEL7 with this (even if it is just a crash) - and the author is on the hook because the only use for the code was educational and "crashing a system"?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: