<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Vulnerability Auction</title><link>http://blogs.technet.com/rhalbheer/archive/2007/07/06/vulnerability-auction.aspx</link><description>I wrote several times already about responsible disclosure and irresponsible disclosure. My point on that is clear: Every vendor has to have transparent and clear processes to handle vulnerabilities. These processes ensure that there will be a timely</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Sold to bidder number 42!</title><link>http://blogs.technet.com/rhalbheer/archive/2007/07/06/vulnerability-auction.aspx#1462096</link><pubDate>Sat, 07 Jul 2007 04:22:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1462096</guid><dc:creator>E-Bitz - SBS MVP the Official Blog of the SBS "Diva"</dc:creator><description>&lt;p&gt;The marketplace of zero days just opened up ... somehow this just doesn&amp;amp;#39;t feel right.... WabiSabiLabi&amp;amp;#39;s&lt;/p&gt;
</description></item><item><title>re: Vulnerability Auction</title><link>http://blogs.technet.com/rhalbheer/archive/2007/07/06/vulnerability-auction.aspx#1488960</link><pubDate>Tue, 10 Jul 2007 02:53:44 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1488960</guid><dc:creator>Alex "Achito" Tunon</dc:creator><description>&lt;p&gt;This is a truly pathetic state of affair we live in where something like this can be allowed to exist. &amp;nbsp;I whole-heartedly agree with you, Roger, and I believe it is OUR responsibility as IT consultants to speak up and educate our clients that garbage as this exists and is costing THEM money because they must continue to increase spending on security.&lt;/p&gt;
&lt;p&gt;While having people &amp;quot;black-hat&amp;quot; systems CAN be a tremendous benefit, it MUST be done ethically and in a controlled manner, and those that do not do so, should be made to pay.&lt;/p&gt;
&lt;p&gt;But that's just my two cents worth....ok...maybe ten cents.&lt;/p&gt;
&lt;p&gt;Achito&lt;/p&gt;
</description></item><item><title>Leilão de Vulnerabilidades</title><link>http://blogs.technet.com/rhalbheer/archive/2007/07/06/vulnerability-auction.aspx#1496060</link><pubDate>Tue, 10 Jul 2007 21:46:11 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1496060</guid><dc:creator>Carlos Fernando Paleo da Rocha&lt;br /&gt;SBS MVP in Brazil</dc:creator><description>&lt;p&gt;Era s&amp;#243; o que faltava, pois agora n&amp;#227;o falta mais. Uma empresa registrada na Sui&amp;#231;a ( &lt;a rel="nofollow" target="_new" href="http://www.wslabi"&gt;http://www.wslabi&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>Vulnerability Auctions</title><link>http://blogs.technet.com/rhalbheer/archive/2007/07/06/vulnerability-auction.aspx#1506723</link><pubDate>Thu, 12 Jul 2007 10:46:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1506723</guid><dc:creator>Microsoft Switzerland Security Blog</dc:creator><description>&lt;p&gt;A group of security professionals launched this week what they hope will become the eBay of security&lt;/p&gt;
</description></item><item><title>Bluehat 2007 Fall Sessions </title><link>http://blogs.technet.com/rhalbheer/archive/2007/07/06/vulnerability-auction.aspx#2061897</link><pubDate>Thu, 27 Sep 2007 22:05:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2061897</guid><dc:creator>Roger's Security Blog</dc:creator><description>&lt;p&gt;I am in Redmond at the moment for internal meetings. We have been able to align these meetings with the&lt;/p&gt;
</description></item><item><title>WabiSabiLabi and their view on ethics</title><link>http://blogs.technet.com/rhalbheer/archive/2007/07/06/vulnerability-auction.aspx#2364620</link><pubDate>Thu, 08 Nov 2007 10:27:05 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2364620</guid><dc:creator>Roger's Security Blog</dc:creator><description>&lt;p&gt;I commented on that already twice and I stated that WabiSabiLabi seems to have a different view on ethics&lt;/p&gt;
</description></item><item><title>Selling Vulnerabilities and Ethics</title><link>http://blogs.technet.com/rhalbheer/archive/2007/07/06/vulnerability-auction.aspx#3057073</link><pubDate>Sun, 18 May 2008 22:19:46 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3057073</guid><dc:creator>Roger's Security Blog</dc:creator><description>&lt;p&gt;Shoaib just blogged on Hacking &amp;amp;amp; Security Community - Ethical or Unethical? . To start with: I do&lt;/p&gt;
</description></item></channel></rss>