Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Information-Security-News
[Top] [All Lists]

[ISN] FrSIRT Puts Exploits up for Sale

Subject: [ISN] FrSIRT Puts Exploits up for Sale
Date: Thu, 16 Mar 2006 04:03:20 -0600 (CST)
http://www.eweek.com/article2/0,1895,1938511,00.asp

By Ryan Naraine 
March 15, 2006 

Independent security research outfit FrSIRT.com is putting its
database of security exploits behind the paid curtain.

FrSIRT, previously known as K-Otik, has shut down the public exploits
section of its Web site and announced that all exploits and
proof-of-concept code will be sold through its subscription-based VNS
(Vulnerability Notification Service).

The 3-year-old company, which operates out of Montpellier, France, is
considered the go-to place for finding exploit code for known software
vulnerabilities and has been a thorn in the side of many vendors,
including Microsoft.

FrSIRT describes itself as the trusted center for the collection and
dissemination of information related to network threats,
vulnerabilities, exploits and incidents, but critics say the company's
open approach to releasing harmful exploit code borders on
"irresponsible disclosure."

The new FrSIRT VNS offers round-the-clock monitoring of new
vulnerabilities and threats, and promises real-time access to a
Web-based security alerting service.

The alerts are delivered through a Web portal, XML feeds and e-mail
subscriptions. Subscribers will also get an online vulnerability
scanner and scheduler with which to run security scans on a regular
basis to check for security vulnerabilities.

FrSIRT said pricing for the service will vary based on the number of
users that will be licensed to receive the alerts and access the
exploit code samples.

The new service is part of a growing trend among third-party
researchers to profit from code auditing work. Companies like iDefense
and Tipping Point have found a lucrative business in purchasing the
rights to information on vulnerabilities.

Dutch security firm Frame4 Security Systems is also getting into the
malware-for-sale market, launching a project called MD:Pro that offers
access to thousands of downloadable malware samples.



_________________________________
InfoSec News v2.0 - Coming Soon! 
http://www.infosecnews.org 

<Prev in Thread] Current Thread [Next in Thread>
  • [ISN] FrSIRT Puts Exploits up for Sale, InfoSec News <=