Full Disclosure mailing list archives

Re: Selling codes exploiting 0-days vulnerabilities


From: Shyaam <shyaam () gmail com>
Date: Sun, 27 Jan 2008 03:09:57 +0000

lol, since when did this become legal and open. Seems like world is
improving for the betterment.........haha

On Jan 27, 2008 1:09 AM, T Biehn <tbiehn () gmail com> wrote:

Do you accept Western - Union 409 payments to your priest friend in
nigeria?
On a more serious note, how do you reach a contractual agreement with
the purchaser before the transfer of money and code? Do you verify
identities or is this more of a sort of e-drug dealing type of thing?
How is the purchaser assured of receipt of exploit details, what sort
of buyer assurances do you provide?

Let us know on-list, perhaps we can stimulate a conversation about
appropriate methods for independent exploit brokerage!

Sincerely,

Travis
On Jan 26, 2008 6:58 PM, Gerrit-Jan Nieuwegein <gj.nieuw () gmail com> wrote:
Hi All,

My name is Gerrit-Jan. I'm posting this message because I'm security
engineer which codes some "exploits" about 0-days vulnerabilities.
Through
this mailing-list, I'm selling these codes. For the moment, I have
interesting exploits for Windows, UNIX and Linux.
Feel free to contact me by e-mail (only if you are interested).

Have nice day,

Cheers,

G.J.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: