pen-test
[Top] [All Lists]

Re: Trend Micro's Vista "0day exploit auction" claim

To: pen-test@securityfocus.com
Subject: Re: Trend Micro's Vista "0day exploit auction" claim
From: krymson@gmail.com
Date: 19 Dec 2006 21:25:33 -0000
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Resent-date: Tue, 19 Dec 2006 13:21:59 -0700 (MST)
Resent-from: pen-test-return-1078483257@securityfocus.com
Resent-message-id: <20061219202159.C49A5243993@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Not only that, but the "first" 0day exploit for Vista can put a security 
company on the map as well. That's worth some money to marketing. Ethical? Not 
really their own research? Perhaps...


<-snip->
Anything is possible. Whether or not it's FUD is totally irrelevant IMHO.
Considering Vista officially launched on November 30*, what's the number
of deployed servers at the moment?
How many of these will be business/mission critical (thus "interesting")?

Sure, the "bad guy" paying 50k for the exploit can sit around waiting for
vulnerable vista's to pop up but if they're willing to pay that price they
should get a developer/security researcher, lock him up in a basement with
a server running vista and get (possibly) more (then 1) 0-day exploit(s).

Kr

Roger

<Prev in Thread] Current Thread [Next in Thread>