Aug 26
Masters singIn an effort to learn more about the OSVDB and vulnerabilities in general, I applied to be a data mangler.
First off a definition:

Data Mangler: A "Data Mangler" is person whose responsibility is to mangle, or edit, a number of vulnerabilities each and every day. Data Manglers do a large amount of technical writing.

The documentation is pretty decent and the backend is very easy to use. It does require a lot of reading and it took me about 1.5 hours to mangle my first entry, and about 40 minutes to mangle the second. My profile is here, you get one point per successfully mangled vulnerability.

I have had three mangles accepted so far. They were both positive learning experiences, particularly about the specifics of exploitation, exploit dissemination and hacking groups, all things I have an idea of but researching them gives me much more insight. They are:
For a working exploit of the Winamp vulnerability go here. The executable it loads is the default windows calc.exe so nothing dodgy. I was quite interested to note that Norton Antivirus blocked this exploit not because the executable was malicious but because of the way it was opened.

Posted by Dominic White

Last modified on 2004-09-09 11:39

0 Trackbacks

  1. No Trackbacks

1 Comments

Display comments as(Linear | Threaded)
  1. No comments

Add Comment


E-Mail addresses will not be displayed and will only be used for E-Mail notifications

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA