Vulnerability Development mailing list archives

Re: 0-day exploit..do i hear $1000?


From: Jose Nazario <jose () biocserver BIOC cwru edu>
Date: Fri, 19 Oct 2001 12:30:50 -0400 (EDT)

On Fri, 19 Oct 2001 foob () return0 net wrote:

Why would a security firm pay someone any money at all for an exploit?

well, one reason would be to have unique information for their intrusion
detection engines or for their pen testing teams. payback is almost
immediate there.

i fully expect infosec companies to start contracting to hacking groups
for idea, exploits and info. its profitable all around, and in this era of
returning to the underground (damn, why did i use my real name this whole
time!!!) it may be what happens.

____________________________
jose nazario                                                 jose () cwru edu
                     PGP: 89 B0 81 DA 5B FD 7E 00  99 C3 B2 CD 48 A0 07 80
                                       PGP key ID 0xFD37F4E5 (pgp.mit.edu)


Current thread: