Online auction house WabiSabiLabi has been created in order to prevent flaws getting in to the hands of hi-tech criminals by rewarding researchers that find them. There is known to be a ready market for vulnerabilities on the digital underground. Many criminal groups prefer to use vulnerabilities for their own ends to steal information or hijack computers rather than have any malicious hacker using them. The independent auction house aims to staunch the flow of vulnerabilities to the underground by giving security researchers a legitimate marketplace for what they find.
Herman Zampariolo, head of WabiSabiLabi added that it could tempt many researchers to report findings they would otherwise keep quiet about, meaning many more vulnerabilities get reported. Once a vulnerability is reported, WSLabi will confirm it is real and that it can be exploited. After this it will be placed on the auction site where it can be sold to the highest bidder or sold to just one firm. WSLabi said it would ensure that all those who buy the vulnerabilities were legitimate.
News source: BBC News
Herman Zampariolo, head of WabiSabiLabi added that it could tempt many researchers to report findings they would otherwise keep quiet about, meaning many more vulnerabilities get reported. Once a vulnerability is reported, WSLabi will confirm it is real and that it can be exploited. After this it will be placed on the auction site where it can be sold to the highest bidder or sold to just one firm. WSLabi said it would ensure that all those who buy the vulnerabilities were legitimate.
















there is no good or legitimate reason for this website to even exist
http://www.wslabi.com/wabisabilabi/initPublishedBid.do?
Bids on Linux vulnerability and some mail app.
Let the exploit-wars begin! Instead of the Cold War we now have an electronic version of it, where the best vuln's are to be had for coin or script.
Express - those listings for the Linux vulns can't be true and honest; I've had people tell me for years that there aren't any vulns for Linux, and that's why (in their own words) "Linux pwns Windows".
this is bad for all reasons, no good can come of this. whoever pays the most money gets to exploit the vbulnerability first and make the most money from it. bad bad bad. bad idea.
What I don't really understand is - what is the market for vulnerabilities? Sure, the company who's product is vulnerable will value it, but the only other people who will are hackers, who are excluded from this auction system...
Last edited by eAi on 09 Jul 2007 - 00:44
2- ?????
3- PROFIT!!
The MANUFACTURER si the only person that NEEDS to know about a vulnerability, any other use is going to be dodgy.
Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!
Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.