Don Parker Blog RSS

All Blogs  »  Don Parker Blog  »  Security Central  »  Blog article: FrSIRT no longer offers freely available exploit code

FrSIRT no longer offers freely available exploit code

It was rather alarming to me when I heard that renowned online exploit archive site www.frsirt.com was no longer going to make public and freely downloadable the exploit code they hosted. The FrSIRT site is much more then simply an exploit code repository, however it is best known for the exploit code that it hosts.

The reason given by the site is that in order to comply with French law they were forced to no longer offer free and public access to the exploit code. You can still however have access to it should you be a subscriber to one of their services. It really is rather sad when one of the oldest democracies in the world comes to this.

Having such a quality central repository for exploit code was very handy, and of value to the computer security community. I for one went there all the time, and downloaded some of the code to play with in my lab. Sadly for me this will no longer be the case. That said I have no intentions of paying for a service so that I can still get it from them. There are still many other sites out there which host exploit code.

The only problem with some other sites is that often the code hosted is purposely obfuscated so that it does not compile. This is normally simple to fix, but for those out there without basic programming knowledge you are out of luck. Should you be in that situation then you may want to post on www.security-forums.com asking for help in getting it running. Forcing websites to remove exploit code is not a cure for anything, much like suing exploit researchers only makes things worst for computer security.

2 Responses to “FrSIRT no longer offers freely available exploit code”

  1. Willie Says:

    March 21st, 2006 at 7:12 pm

    Kind of Big Brother’ish, huh? I think it’s in the air… I just read at some other forum that according to UK law it’s illegal if you don’t have all of the passwords to encryption software you use handy. I might have read it in this forum. Can you believe that?

  2. Don Parker Says:

    March 22nd, 2006 at 5:13 am

    I agree that it is ridiculous. As to the p/w’s for ecyption I remember reading that too. Believe it was due to the fact that the police must be able to decrypt it if needed or somesuch. Though I agree the police need to do their job it does seem a little much surely.

    Salut!

    Don

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a




Receive all the latest articles by email!

Receive Real-Time & Monthly WindowSecurity.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowSecurity.com member!

Discuss your security issues with thousands of other network security experts. Click here to join!

Community Area

Log in | Register

Solution Center