zeroBay Exists: Will The Juice Be Worth The Squeeze?

Dave G. | July 6th, 2007 | Filed Under: Disclosure

Dark Reading reports that Wabisabilabi is open for business as the first public auction site for vulnerabilities.

From the time I was young, my father would tell me this story about how there was a city that was having a city planning problem. The planning committee worked on the problem and couldn’t come up with a solution. One day, someone said they had the solution to the problem and would gladly tell the city for 1,000,000$. The city refused, but by simply knowing that there a solution, they took another crack at it and eventually found a way to solve the problem. Please believe me that my dad tells this story in a way that is more more compelling, but you get the basic idea.

Vulnerability markets can be like this, except it is a problem people didn’t even know that they had. For example, here is a screen capture:

Picture 51.jpg

Now, GPG plugin is a small amount of PHP code (< 10,000 SLOC). How long do you think it will take for someone with reasonable skill to find out where the bug is? I promise you, it won’t take long. Let alone this guy, who would find it if someone were transferring the source via a WiFi connection near him. Now a retail price of 1000$EU might be worth it, but I guarantee you that this bug is burned just because the title gives away enough for someone to do a code review and find that (and whatever else lurks in there).

Now competitive researchers, the vendor and/or potential buyers can just go and find the vulns themselves.

Viewing 11 Comments

Trackbacks

close Reblog this comment
blog comments powered by Disqus