Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
    Digg this story   Add to del.icio.us  
Flaw researcher offers ad space in report
Published: 2006-01-19

A security researcher who previously tried to auction off a vulnerability in Microsoft Excel plans to sell ad space in the public report about the flaw, SecurityFocus has learned.

The researcher has teamed up with security firm HexView to release details of the vulnerability on the same day that Microsoft releases the patch for the Excel flaw, the researcher, who uses the moniker "fearwall", stated in an e-mail to SecurityFocus. The company will hold an auction through e-mail with the highest two bidders getting advertising within in the announcement.

The announcement is the latest attempt by the security researcher to make money from finding a flaw in Microsoft flagship spreadsheet application. Last month, eBay shut down an auction in which the researcher attempted to sell information about the vulnerability. The online auctioneer closed down a second sale linked to the vulnerability, despite some feelings within the security community that auctioning vulnerability information could lead to better security.

The debate over what is responsible disclosure continues: In 2005, independent researchers and software companies disputed the value of public disclosure, most famously when former Internet Security Systems researcher Mike Lynn described a method to run code on a Cisco router.



Posted by: Robert Lemos
    Digg this story   Add to del.icio.us  
 
Comments Mode:







 

Privacy Statement
Copyright 2008, SecurityFocus