Re: [Full-disclosure] IE 0day for sale

2009-12-12 Thread Gregor Schneider
2009/12/12 Jeff Williams jeffwilli...@gmail.com: And the question is now: should the Mossad, NSA, etc be considered as bad guys ? that is a definately YES gregor -- just because your paranoid, doesn't mean they're not after you... gpgp-fp: 79A84FA526807026795E4209D3B3FE028B3170B2 gpgp-key

[Full-disclosure] IE 0day for sale

2009-12-11 Thread Freddie Vicious
Hello list, I offer a 0day exploit on Microsoft Internet Explorer, versions 8, 7, 6. Tested on Windows 2000/XP/2003/Vista/2008/7. Serious offers only, no bullshit please :) -- Best wishes, Freddie Vicious http://twitter.com/viciousf ___

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread Valdis . Kletnieks
On Fri, 11 Dec 2009 18:23:54 +0200, Freddie Vicious said: I offer a 0day exploit on Microsoft Internet Explorer, versions 8, 7, 6. Tested on Windows 2000/XP/2003/Vista/2008/7. Serious offers only, no bullshit please :) Extraordinary claims require extraordinary proof - so convince us that you

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread Freddie Vicious
Mr. Valdis Kletniesks, I'll provide proof only for serious bidders. As I said, no bullshit please. On Fri, Dec 11, 2009 at 6:38 PM, valdis.kletni...@vt.edu wrote: On Fri, 11 Dec 2009 18:23:54 +0200, Freddie Vicious said: I offer a 0day exploit on Microsoft Internet Explorer, versions 8, 7,

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread yaroslav
Send them to microsoft, pls. Or sell to zdi. This is a very serious offer, absolutely no bs. Hello list, I offer a 0day exploit on Microsoft Internet Explorer, versions 8, 7, 6. Tested on Windows 2000/XP/2003/Vista/2008/7. Serious offers only, no bullshit please :) -- Best wishes,

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread Benji
Free dorrar? Sent from my iPhone On 11 Dec 2009, at 16:23, Freddie Vicious fred.vici...@gmail.com wrote: Hello list, I offer a 0day exploit on Microsoft Internet Explorer, versions 8, 7, 6. Tested on Windows 2000/XP/2003/Vista/2008/7. Serious offers only, no bullshit please :) -- Best

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread Michael Lenz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 If there was proof, I'd bid. But as there is none and you don't intend to disclose any proof without a prior bid.. Freddie Vicious schrieb: Mr. Valdis Kletniesks, I'll provide proof only for serious bidders. As I said, no bullshit please. On

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread Thor (Hammer of God)
: [Full-disclosure] IE 0day for sale Mr. Valdis Kletniesks, I'll provide proof only for serious bidders. As I said, no bullshit please. On Fri, Dec 11, 2009 at 6:38 PM, valdis.kletni...@vt.edumailto:valdis.kletni...@vt.edu wrote: On Fri, 11 Dec 2009 18:23:54 +0200, Freddie Vicious said: I offer

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread Nelson Brito
...@vt.edu Cc: full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] IE 0day for sale Bids for what? An exploit? What does it to? How does it do it? What context does code run (assuming code runs). What do you have to trick the user into doing? Do you actually think people

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread mrx
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Freddie Vicious wrote: Hello list, I offer a 0day exploit on Microsoft Internet Explorer, versions 8, 7, 6. Tested on Windows 2000/XP/2003/Vista/2008/7. Serious offers only, no bullshit please :)

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread Shyaam
If you are really serious about selling, you should sell it to ZDI or iDefense. They do pay good money and it doesnt reach the bad hands, and it guarantees your money. Thats my 2 cents. On Fri, Dec 11, 2009 at 4:23 PM, Freddie Vicious fred.vici...@gmail.comwrote: Hello list, I offer a 0day

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread Jeff Williams
zdi,idefense,securiteam,immunity,etc is a front, your exploit will anyways end up on the blackmarket by selling it to theses company. How can you be that naive ? 2009/12/11 Shyaam shy...@gmail.com If you are really serious about selling, you should sell it to ZDI or iDefense. They do pay

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread Valdis . Kletnieks
On Fri, 11 Dec 2009 20:13:52 EST, Jeff Williams said: zdi,idefense,securiteam,immunity,etc is a front, your exploit will anyways end up on the blackmarket by selling it to theses company. How can you be that naive ? You're talking to somebody willing to sell to the highest bidder on F-D. Draw

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread Jeff Williams
If idefense pay 7000$ for a RCE on IE, it's possibly because they sell theses bugs to the NSA, MOSSAD, MI10 ? From my understanding, MS do not pay for any reported vulnerability, or maybe i missed the make a donation icon on idefense website ? 2009/12/12 Shyaam shy...@gmail.com :) Good one

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread Jeff Williams
And the question is now: should the Mossad, NSA, etc be considered as bad guys ? 2009/12/12 Jeff Williams jeffwilli...@gmail.com If idefense pay 7000$ for a RCE on IE, it's possibly because they sell theses bugs to the NSA, MOSSAD, MI10 ? From my understanding, MS do not pay for any

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread jack . a . mannino
] IE 0day for sale ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ ___ Full-Disclosure - We believe