Michael Sutton
Michael Sutton
capability code create default difficult display exploit generally image instead media page player public render ripe target though uses web windows
Even though Windows Media Player is not something generally used to render images, it has the capability of doing that. It's not difficult to create a Web page that uses Windows Media Player to display an image instead of the default application. I think it's a ripe target for exploitation if we see public exploit code for it.
credited encourage looking reporting
In 2005, we were credited with reporting 3 'critical' vulnerabilities to Microsoft, and we want to encourage our contributors to keep looking in that direction.
drank drinking
He wasn't even drinking or anything. Never drank before.
code expect exploit public
Patching is very urgent. We expect public exploit code to become available, especially for the MSDTC issue.
code followed handle libraries media portions seems sure surprise
It seems like there is some flaky code in portions of the libraries that handle the WMF files. It wouldn't surprise me if we see more vulnerabilities emerge, which I am sure will be followed by more media coverage.
aware code exploit public
We're not aware of any public exploit code for it at this time.
code free information model pay quite researcher review wants
The only model that makes no sense to me is the altruistic model. The vendor wants the researcher to do his code review for free and that doesn't quite fly. They are profiting from the vulnerability information but they don't want to pay for it.