<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ClearNet Security: The booming exploit market and bye bye to swaths of products</title>
    <link>http://blog.clearnetsec.com/articles/2008/01/31/the-booming-exploit-market-and-bye-bye-to-swaths-of-products</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>The booming exploit market and bye bye to swaths of products</title>
      <description>&lt;p&gt;
There are lots of articles mentioning the &lt;a href="http://www.digitalarmaments.com/challenge200801566321.html"&gt;Digital Armaments bounty for exploits&lt;/a&gt;.  I wrote a &lt;a href="http://blog.clearnetsec.com/articles/2007/12/28/%E2%80%9Cbig-money-big-prizes-i-love-it-%E2%80%9D"&gt;snippet&lt;/a&gt; on the commercial exploit market about a month ago, whereby I was simply listing the prices for subscribing to the different exploit houses.
&lt;/p&gt;
&lt;p&gt;
I guess I forgot to consider another complexity of all this and that is from the influence the organizations who compete to purchase exploits are having (e.g.  iDefense, 3COM/TippingPoint, Governments, people and groups w/lots of money).  
&lt;/p&gt;
&lt;p&gt;
I wonder how extensive this really goes &#8211; I mean, it seems this market is in a boom of sorts which implies there are lots of private exploits trading hands.  Exactly how many would be interesting to know.  Hell, any numbers would be nice.    
&lt;/p&gt;
&lt;p&gt;
One thing is apparent though, if this market continues to grow then how can any security products based on &#8220;knowing attacks&#8221; succeed?  They won't.  An IDS vendor is not going to be able to afford to purchase all; no company will have a monopoly.  


</description>
      <pubDate>Thu, 31 Jan 2008 23:50:00 -0700</pubDate>
      <guid isPermaLink="false">urn:uuid:656fdeec-7440-4a99-94be-62030c0fa12e</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2008/01/31/the-booming-exploit-market-and-bye-bye-to-swaths-of-products</link>
      <category>security</category>
      <category>ClearNet</category>
      <category>ClearNet Security</category>
      <category>Tate Hansen</category>
      <category>ids</category>
      <category>ips</category>
      <category>exploits</category>
      <category>vulnerabilities</category>
    </item>
  </channel>
</rss>
