When They Said "Get It On eBay", I Doubt This Is What They Meant
from the W32.this-space-for-rent.P@mm dept
The idea of using security exploits to make some cash certainly isn't anything new -- online extortion schemes have been fairly popular, even if script kiddies are killing the margins. But apparently discovering security vulnerabilities and selling them off to the highest bidder is a growth industry, according to one security firm, even being brazen enough to put them up on eBay. It's hardly surprising to see hackers and malware writers searching for some remuneration for their efforts, particularly with the explosion in phishing, identity theft and other potenially lucrative crimes, and their dependence on staying a step ahead of security companies. What's slightly more interesting, though, is that many security companies themselves are shelling out for the vulnerabilities, under the guise of the greater good, but really getting the information to give themselves a head start in closing the vulnerabilities, and enhancing their products and reputation. Economists love to talk about the value of incentives in motivating people to particular behavior -- perhaps giving malware authors incentives to turn their work over to software developers or security companies isn't such a bad idea.
50 Comments | Leave a Comment..
- iPhone Developer Creates App Criticizing The iPhone; App Is Quickly Pulled
- Leaked HBGary Documents Show Plan To Spread Wikileaks Propaganda For BofA... And 'Attack' Glenn Greenwald
- Publishers Remove 2500 Journals From Free Access In Bangladesh; Put Them Back When People Notice
- Just Weeks After Cutting Off Wikileaks, Amazon Brags About How US Federal Gov't Is One Of Its Biggest AWS Customers?
- Oh Look, Police Can Investigate A Satirical Online Comment About Mythical Violence And Not Overreact





Reader Comments (rss)
(Flattened / Threaded)
[ reply to this | link to this | view in thread ]
good idea
[ reply to this | link to this | view in thread ]
Profitability VS Responsibility
[ reply to this | link to this | view in thread ]
That's the way (ah huh) I like it
I probably have $20,000 in free legal software now and to me makes better sense to help the companies than some stupid loser high school kids that does not get it.
Find the flaw and work with the business is the only way to do it right, plus you get better "street cred" than those idiots out there.
[ reply to this | link to this | view in thread ]
Re:
[ reply to this | link to this | view in thread ]
It's Not Renumeration
1. The act of remunerating.
2. Something, such as a payment, that remunerates.
[ reply to this | link to this | view in thread ]
not good...
This is just another incentive to CONTINUE their deplorable practice. Though I suppose it does keep a lot of people employed.
[ reply to this | link to this | view in thread ]
Re: not good...
[ reply to this | link to this | view in thread ]
Make secure code
[ reply to this | link to this | view in thread ]
Re: That's the way (ah huh) I like it
[ reply to this | link to this | view in thread ]
Catch Me if You Can
Leo's character forged checks, and the FBI was after him. Once they found him, they made them help detect bad checks, and develop ways to test new checks for vurnabilities. It is quite nice to see someone "turn around" and hopefully crime will stop in the future. here's to dreaming
[ reply to this | link to this | view in thread ]
Re: Make secure code
You may be a programer but have you ever created an OS? I would bet not .. and I'd bet that you haven't had to create a program that runs on the majority of PC's world wide. But I may be wrong you may be some super intellect that is able to predict the future.
MS is easy to pick on simply because they are everywhere. They are everywhwere because the majority of people think their product is better than the competition.
[ reply to this | link to this | view in thread ]
[ reply to this | link to this | view in thread ]
Re: Re:
Turn off anonymous comments and turn on registration and moderation.
[ reply to this | link to this | view in thread ]
Re: It's Not Renumeration
[ reply to this | link to this | view in thread ]
Ok back on topic
Sounds like a new job to me! I agree dont pay them but reward them with a copy of the software. Gets them using it and doesnt make an industry out of it.
Stop the MS bashing I can show you time and again where *nix and MAC have security holes the size of MS campus. To sit and think for a moment that one OS is better then the next is retarded. ALL digital information that is secure can be hacked and all the same info that is not secure can be hacked if you think your Linux is safe I will personally send you to sites dedicated to hacking *nix as its even easier to do. MAC = LINUX ro WINDOWS so your last people who can speak now.
[ reply to this | link to this | view in thread ]
Re: Re: It's Not Renumeration
http://www.wsu.edu/~brians/errors/remuneration.html
[ reply to this | link to this | view in thread ]
Re: It's Not Renumeration
The act of numbering something that has already been numbered.
[ reply to this | link to this | view in thread ]
Good idea
But definitely don't offer money but instead free copies of the software. That why they know they are using a secure product (because they are one ones testing it) and it builds trust with that developer.
Only problem is if it became public (out in the open on the net) that you're doing this then you would treated as a narc.
[ reply to this | link to this | view in thread ]
Re: Re:
Oh yeah! I'm in for the 20th post!!!
[ reply to this | link to this | view in thread ]
Re: Re: Re:
[ reply to this | link to this | view in thread ]
nice
[ reply to this | link to this | view in thread ]
Re: Ok back on topic
As for the bashing, I have to agree with an earlier poster. Among other things I'm a system engineer and have designed and written my own OS, database servers, and application suites over the last three decades. While no one has found a bug or security hole to date, it sure wasn't easy although coming from the mainframe world where zero defects is de rigueur sure helps. The design and mathematical validation easily took ten times longer than the actual coding and testing. So does the threat of federal time if you frag up {smile}. I do get to see the security notices march by day in and day out, naturally since systems security is one of my main focii these days. Windows is just a better target, so it gets most of the savaging. It also helps that the codebase for Linux is significantly smaller at the kernal level. Lastly, Windows incorporates a lot of applications into the OS that are not in Linux directly. Toss in Linux applications to the mix for vulnerabilities and the numbers get more comprable.
Actually I get damned tired of this "my OS is better than your OS, nah, nah" BS. All of them are weak, Windows, Linux, and Mac, when it comes to overall (OS and applications) security. If I tried to get away with this crap when I was working for the government somebody would have died and they'd be considering whether it would be life in prison without the possiblity of parole or hanging.
Ever wonder why there are life/nuclear critical exclusions in so many operating systems and applications license agreements? Your bug, you go to prison.
[ reply to this | link to this | view in thread ]
[ reply to this | link to this | view in thread ]
Re: Re: Re:
[ reply to this | link to this | view in thread ]
[ reply to this | link to this | view in thread ]
Cut off their hands
[ reply to this | link to this | view in thread ]
Re: Re:
[ reply to this | link to this | view in thread ]
Well...
But all in all, this selling malware shit on e-Bay is fucked. I think these auctions should be shut down and the owner of the account IP banned. Even though IP bans really dont do much anymore with Proxies.
[ reply to this | link to this | view in thread ]
It would help if we would step across borders on t
It has gotten out of control though I do agree that some credit should go to those who find glitches and fix the problems someone may be having.
[ reply to this | link to this | view in thread ]
Reward those who find it and do not exploit it
[ reply to this | link to this | view in thread ]
Spelling....
[ reply to this | link to this | view in thread ]
Re: Re:
[ reply to this | link to this | view in thread ]
[ reply to this | link to this | view in thread ]
yes we need to hold people accountable
If the punishment were anything less it would not be serrious enough. However if Joe Script Kiddie or Bob Anonymous Hacker thought he was gonna fry for being a little bass turd would they be so willing to take their shot? Or would they find a new hobby or maybe get a real job ...
[ reply to this | link to this | view in thread ]
Did you change the headline of this article?
When They Said "Get It On eBay", I Doubt This Is What They Meant
I just thought it's kinda odd to see this changed without any note on the page...
[ reply to this | link to this | view in thread ]
Post 36
[ reply to this | link to this | view in thread ]
g
[ reply to this | link to this | view in thread ]
Is this a Joke?
"from the W32.this-space-for-rent.P@mm dept"
[ reply to this | link to this | view in thread ]
"from the W32.this-space-for-rent.P@mm dept"
oh noez, teh scriptoz kidde1s f0und us
[ reply to this | link to this | view in thread ]
Re: Re: Make secure code
True. No one CARES that they dont have secure software, exept people like me. That is because the majority of people are STUPID. (no offense stupid people)
Smart people like me care. If more people were smart, and therefor cared, MS couldn't get by with they're bad software.
[ reply to this | link to this | view in thread ]
Re: to marks comment
that includes u
[ reply to this | link to this | view in thread ]
Re: Re: Ok back on topic
[ reply to this | link to this | view in thread ]
Re: Post 36
[ reply to this | link to this | view in thread ]
Re: Profitability VS Responsibility
[ reply to this | link to this | view in thread ]
About the sub headline. When new exploits are found most anti-virus software makers give the exploits a name. Something that reflects the OS that it targets...W32. Then the exploit name...this-space-for-rent. Then I think it's the version...P@mm( this would P mutation or verison or such).
[ reply to this | link to this | view in thread ]
[ reply to this | link to this | view in thread ]
Re: Re:
2. someone posts
3. first post gets deleted
4. goto 2
???
5. PROFIT!!!!
[ reply to this | link to this | view in thread ]
Re:
[ reply to this | link to this | view in thread ]
Re: Re:
[ reply to this | link to this | view in thread ]
Add Your Comment