On Wed, 10 Aug 2005 01:34:30 EDT, "Roger A. Grimes" said:
> Well, since at least one known vendor (eEye) publicly said they reversed
> engineered one of the patches in 1-hour after looking at the patch for
> the first time, why believe otherwise? It's not impossible simply
> because you can't do it.

On the flip side, just, because *one* vendor did that for *one* patch doesn't
mean that *every* PoC gets created that way, unless you've taken a hit
of the Microsoft kook-aid.

Let's face it - if *all* of them are clever enough to reverse-engineer the
patch, at least *some* of them are clever enough to have found the hole without
a patch to guide them.  And once it's not a 0-day anymore, you might as well
get visibility by releasing it and claiming you're a rev-engineering marvel....
