<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Technology Liberation Front - Latest Comments in eBay for Black Hats?</title><link>http://tlf.disqus.com/</link><description>The Technology Liberation Front is the tech policy blog dedicated to keeping politicians' hands off the 'net and everything else related to technology.</description><atom:link href="https://tlf.disqus.com/ebay_for_black_hats/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Sun, 17 Dec 2006 23:00:35 -0000</lastBuildDate><item><title>Re: eBay for Black Hats?</title><link>http://techliberation.com/2006/12/16/ebay-for-black-hats/#comment-1449026</link><description>&lt;p&gt;There's a very real miscreant economy, and many things, including exploits, access to botnets for DDoS (useful for extortion, etc.), and so forth are bought and sold daily.  I've never heard of an exploit going for $50K, but they do go for amounts into the thousands.&lt;/p&gt;&lt;p&gt;I've never heard of anything like an 'eBay' for miscreants', most of the transactions are negotiated over IRC and IM, AFAIK.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Roland Dobbins</dc:creator><pubDate>Sun, 17 Dec 2006 23:00:35 -0000</pubDate></item><item><title>Re: eBay for Black Hats?</title><link>http://techliberation.com/2006/12/16/ebay-for-black-hats/#comment-1449028</link><description>&lt;p&gt;Who says auction system? There are ways of doing auctions without software, you know :) Anonymized chat room (which they are already very good at doing anonymously/untraceably, to control the botnets) + chatters saying 'I'll bid X' 'Do I hear X+1?' 'X+1!' You know, the old fashioned way :)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Luis Villa</dc:creator><pubDate>Sun, 17 Dec 2006 07:08:05 -0000</pubDate></item><item><title>Re: eBay for Black Hats?</title><link>http://techliberation.com/2006/12/16/ebay-for-black-hats/#comment-1449027</link><description>&lt;p&gt;I have to agree with Tim. I find it hard to believe that people who have the programming knowledge to engineer exploits to operating systems would trust any type of online auction system. Seems like a nice plot for a novel though.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David</dc:creator><pubDate>Sat, 16 Dec 2006 23:22:25 -0000</pubDate></item><item><title>Re: eBay for Black Hats?</title><link>http://techliberation.com/2006/12/16/ebay-for-black-hats/#comment-1449029</link><description>&lt;p&gt;Right, but doesn't putting your exploit up for auction substantially increase the chances of getting caught? I can believe that these exploits could be worth 50 grand, but I wouldn't think an online auction would be the way you'd sell them.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tim Lee</dc:creator><pubDate>Sat, 16 Dec 2006 22:10:45 -0000</pubDate></item><item><title>Re: eBay for Black Hats?</title><link>http://techliberation.com/2006/12/16/ebay-for-black-hats/#comment-1449030</link><description>&lt;p&gt;I've heard of such things for earlier versions of Windows before, including some reputable/documented stories of auctions of botnets. Their existence shouldn't be too surprising- get that zero day exploit, and you can get yourself a very profitable botnet. Given the reputed cash flow for some of the spam kings, $50K doesn't sound implausible. And of course they are already in deep legal trouble if caught, so an additional charge wouldn't scare them very much.&lt;/p&gt;&lt;p&gt;The only part of this that sounds implausible is that it is for Vista- there is no commercial value in hacking into undeployed systems. But maybe they'll just stockpile it.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Luis Villa</dc:creator><pubDate>Sat, 16 Dec 2006 19:39:42 -0000</pubDate></item></channel></rss>