Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity
    • Development

    Immunity Demos Automatic Exploit Tool

    Written by

    Lisa Vaas
    Published August 8, 2007
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      LAS VEGAS—Immunity, a company already well-known for making pen testing easy, demoed a new tool that will make writing exploits near-automatic.

      Immunity released the tool, called Debugger, here at the Defcon hackers convention on Aug. 3. Debugger is free for download, with its revenue being driven by paid ads from companies looking to hire the pen testers who use such a tool. One of the first help-wanted ads taken out by such companies includes Applied Security.

      Debugger comes with what Immunity says is the industrys first heap analysis tool built specifically for heap creation. It also sports a large Python API for easy extensibility and has function graphing as part of its user interface. The version released on Aug. 3 doesnt yet include stackvars.py, the automatic analysis script, but Immunity demonstrated the script and is showing it on its site.

      Immunity is claiming that Debugger will cut exploit development time by 50 percent.

      Not everybodys happy to hear that.

      “Theyve got a good development community,” said Dave Marcus, security research and communications manager at McAfees Avert Labs, in an interview with eWEEK at Defcon. “But I look at it from the other side of house: What does this mean to the computing public?”

      What it means is more zero days, Marcus said. “And thats certainly not a good thing. I think youll see a spike in zero days, and contributions to the zero-day initiative, because it makes it easier to find vulnerabilities. Youre making the job easier.

      Immunity CEO Dave Aitel doesnt see any problem with helping customers find zero days. As a matter of fact, Immunity trains people to find zero days.

      “Thats something we think all companies should do,” he told eWEEK. “Otherwise youll be sticking your head in the sand.”

      Marcus said he doesnt think that “the bug exists already” argument is a good one. “Yes, we know that,” he said. “We know the bugs are in the code. But making more and more tools” to make it easier to find those bugs, that, he said, is not going to make his customers happy.

      “Theyll all do this,” he said, rolling his eyes to the ceiling. “Great!”

      Of course, there are already fuzzers that track down vulnerabilities that can lead to exploitation. However, until now, writing exploits has been the manual part of it, done in the “tweaking” process, Marcus said.

      /zimages/7/28571.gifRead here about a new application and network security tool from startup Breaking Point Systems.

      Now, the security industry doesnt have to write its own programs to automate the translation of a vulnerability to an exploit.

      “You dont have to learn the Canvas API [another Immunity tool] or how to build exploits,” Aitel promised, as much of the functionality of these tools are built into Debugger.

      Debuggers interfaces include a GUI and a command line thats always available at the bottom of the GUI. This allows users to type shortcuts as if they were in a typical text-based debugger. Immunity has also implemented aliases so that users of its other tools dont have to be retrained and can just leap into using the debugger interface.

      Editors Note: This story was updated to correctly state that the automatic analysis script, although demoed, isnt included in Debugger Version 1. Also, the original story misidentified Applied Security. eWEEK regrets the errors.

      Check out eWEEK.coms Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEKs Security Watch blog.

      Lisa Vaas
      Lisa Vaas
      Lisa Vaas is News Editor/Operations for eWEEK.com and also serves as editor of the Database topic center. She has focused on customer relationship management technology, IT salaries and careers, effects of the H1-B visa on the technology workforce, wireless technology, security, and, most recently, databases and the technologies that touch upon them. Her articles have appeared in eWEEK's print edition, on eWEEK.com, and in the startup IT magazine PC Connection.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×