Security vuln auction site pulls in research
A controversial marketplace for security exploits and vulnerabilities said it has exceeded expectations with the submission of more than 150 vulnerabilities in its first two months of operations. WabiSabiLabi encourages security researchers to sell their findings to vetted buyers. Herman Zampariolo, chief exec of WSLabi which …
This topic is closed for new posts.
Posted Friday 12th October 2007 21:22 GMT
Yeah...right! #
...cause as we all know, the bad guys would never have any money to buy these or have false identities/shell companies with stolen information to purchase vulns with. and $10k? I bet some of the larger spam ops pull that in about an hour.
Here is a question, what if a windows vuln was purchased by bad guys, using fraudulent info and a stolen credit card, and the purchased vuln was then used to exploit windows users and steal more creit card numbers? Like a snake eating itself.
I personally think making vulns a commodity only creates a more harmful environment. Only crappy security vendors buy these and then write signatures to catch one variant of the exploit. What a world.
Posted Saturday 13th October 2007 01:02 GMT
Illegal Methodology #
Reverse engineering illegal? First that I've heard of it!
If the aim is to direct vulnerability research to the good, it also seems to be an odd decision to make. The good guys can't use the same tools? Daft!
This topic is closed for new posts.
Most read
Popular Whitepapers
- Reshaping IT
in a consumer driven era - Register Research on: Application Platforms
The state of play - Secure Mobile Working
Beyond the Technology - Reg Reader Research: SaaS based Email and Office Productivity Tools
A critical look at the promise and practicality for SMBs - The Impact of IT Security Attitudes
Putting the pieces in place for effective security delivery - The Evolving Security Landscape
Reg Webinar
Transforming IT culture
Driving Situational Awareness:
Application Performance Management:
Ensuring service assurance in the new normal