pen-test
[Top] [All Lists]

Re: Trend Micro's Vista "0day exploit auction" claim

To: Radu Oprisan <radu@securesystems.ro>
Subject: Re: Trend Micro's Vista "0day exploit auction" claim
From: Cody Tubbs <tubbs@wispdirect.com>
Date: Tue, 19 Dec 2006 15:40:28 -0800
Cc: pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
In-reply-to: <458870C1.4010307@securesystems.ro>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <002501c7239f$c8603930$3201a8c0@desktop> <458870C1.4010307@securesystems.ro>
Resent-date: Tue, 19 Dec 2006 15:27:11 -0700 (MST)
Resent-from: pen-test-return-1078483259@securityfocus.com
Resent-message-id: <20061219222711.C48A3239034@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
User-agent: Thunderbird 1.5.0.7 (X11/20060918)
It's cheaper to pay kids 50k for actually finding flaws, rather than paying hundreds of QA engineers 60-100k a pop to spend months finding nothing. Another reason M$ sucks, exploit the exploiters.

-Cody Tubbs

Radu Oprisan wrote:
Ryan Meyer wrote:
A number of popular tech news sources are reporting Trend Micro's CTO,
Raimund Genes, publicly claiming that there are "auctions" for zero-day
Windows Vista exploits. Further, he claims these auctions are fetching
approx $50,000.

Could anyone verify Trend Micro's claim?

It seems dubious, at best, to me and possibly nothing more than pure FUD.

Sorry to get off topic.

Ryan Meyer

This could also be some covert way for microsoft to find their own
vulnerabilities. That has happened before.




<Prev in Thread] Current Thread [Next in Thread>