📚 OpenRCE is preserved as a read-only archive. Launched at RECon Montreal in 2005. Registration and posting are disabled.








Flag: Tornado! Hurricane!

 Forums >>  Brainstorms - General  >>  Adequate Crack Proofing vs. Inadequate Coding

Topic created on: August 31, 2006 21:16 CDT by OpsMan .

Hello Brothers, and Sisters.

Hadn't been real active on the forums lately. Reasearching and cathing up on some much needed reading.

It seems so many software vendors put such effort into software anti-reversing/cracking and so little in security. No surprise to many of you I'm sure for the almighty dollar/euro rules. When does it become so ridiculous that the customers demand accountability. As a patron of some really usefull software it baffles/eludes any logical thinking that my money is used to legaly use the not so bug free software. Furthermore my dollar is used against my own attempts to repair such mistakes (conflicts with other programs, crashing altogther, and just freezing up at times) while at the same time I could be allowing someone to infect my system by some stupid vulneraility.

Taking a look at some of the listed vulnerabilities on securityfocus it's astounding. For example, ZoneAlarm is widely used and although you can use it free, the paid program versions suffer from the same vulnerabilities. Now there are several applications with such stupid coding mistakes. I'm not picking on just ZoneAlarm.

So my question is why is it so acceptable for customers to accept such mistakes? I know , you just download the updated patch when such mistakes are reported. I'm damn glad auto companies don't operate like that. And if these vulnerablities are an ever present part of software then why not make it easier for me to correct such mistakes myself and not spend hours of unpacking, decrypting, and debugging.

I guess the Open Source community has the right attitude and we should all support them both with our code and our money.

OpsMan.

  toto22   September 10, 2006 09:17.07 CDT
i think it's also a timing problem. i worked in a little company and did a lot of things including a php intranet -what a not-so-poor company it's not my primary job- and even in a little company, thank you to work on "this" from yesterday to .. today. I'm sure you get my point. And even if a project launch with a big hapy-happy, when months fill out, then people not so happy because finally devels people dont really do what they wanted. It was their job but it was not their timing nor their methods, so it's crap and you want to forget it.

Note: Registration is required to post to the forums.

There are 31,328 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Question about memor...
Dec/12


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit