FEATURED VIDEO

Sponsored By:


SLIDE SHOWS
ChannelWeb's Top 25 Execs of 2008 know that reading is fundamental. Here are their picks for books to feed your brain.
There were plenty of high-powered movers and shakers that made a big impact on the channel in 2008. Here's a look at who made our list of the 25 most influential.
It's time again to agonize over what to get the techie in your life. With the holidays closing in fast, here are 25 gift ideas sure to wow any techie.
INSIDE CHANNELWEB
techcareers logo Search Jobs:


  

Post Resume|Employers

Recent Post:


Regional Desktop Coordinator
BP seeking Regional Desktop Coordinator in Houston, TX
spacer

McAfee Chides TippingPoint In QuickTime Vulnerability Disclosure


CRN logo By Kevin McLaughlin, ChannelWeb
10:03 AM EDT Tue. May. 08, 2007
A McAfee security researcher on Monday criticized 3Com's TippingPoint division for the way it handled the disclosure of a previously unknown vulnerability in Apple's QuickTime streaming media software.

At the CanSecWest conference in Vancouver, B.C., last month, security researcher Dino Dai Zovi won a "hacking contest" by creating a QuickTime exploit and using it to take over a MacBook laptop. Zovi won the MacBook for his efforts and received a $10,000 bounty from TippingPoint's Zero Day Initiative, a controversial program that offers cash rewards to security researchers in return for exploit code.

In a blog post, Rahul Kashyap, a vulnerability researcher at McAfee, called out TippingPoint for paying the bounty and not giving Apple a chance to fix the bug before its regular patch release.

"Wow! It is rather ironic that a security company, who presumably wants to protect customers, will first put everyone to risk, not notify the vendor on time, and then release signatures!" Kashyap wrote in the blog post.

"The antivirus community, long the target of (bogus) claims that they write viruses to make money, wouldn't touch a contest like this with a barge-pole," Kashyap added.

Apple issued a patch for the vulnerability about a week after being notified by the Zero Day Initiative.

Terri Forslof, security response manager at TippingPoint's Digital Vaccine Labs, said the idea behind the bounty was to dispel the rumors and speculation that typically accompany any discussion about how much a security vulnerability is worth.

"We don't advertise our prices. We could have said, 'We'll buy the vulnerability,' but the first question would have been, 'How much is it worth?' " Forslof said.

There's an inherent risk that can be associated with programs like the Zero Day Initiative, said Craig Schmugar, virus research manager with McAfee's Antivirus Emergency Response Team.

Given the attention that Zovi's QuickTime bug has received, hackers are more likely to reverse-engineer Apple's patch, which could soon lead to exploit code appearing in the wild, according to Schmugar.

"Discovery, disclosure and patching [of vulnerabilities] affect everyone on the Internet," Schmugar said.

Roger Thompson, chief technical officer at Exploit Prevention Labs, based in New Kingstown, Pa., said when it comes to exploit code, the more that's discovered, disclosed and patched, the better, which means fears of reverse-engineering shouldn't factor into equation.

"When Microsoft patches every month, the potential exists for people to reverse the patches, but that's hardly an argument that Microsoft shouldn't patch," Thompson said.


RATE THIS ARTICLE Worse 1 2 3 4 5 Better
CHANNELWEB MARKETSPACE >> (Sponsored Links)
Channelweb : Promofinder
FEATURED PROMOTIONS
90% OFF Aladdin SafeWord Starter Pack - Act Now!!
Make more money with SafeWord and Aladdin now that we've joined teams. Order a SafeWord Two-Factor Authentication Starter P...
Get More in Q4 from Kaspersky Lab
Sell Kaspersky products and earn dollars for every sale of 10 or more nodes. That’s right! Every sale you make will put extra...
LATEST NEWS >>
December 01, 2008 06:50 PM
December 01, 2008 04:19 PM
December 01, 2008 03:40 PM
December 01, 2008 11:55 AM
December 01, 2008 10:39 AM
RELATED BLOG >>
Photo
The Test Center's most recent threat watch.
ADVERTISEMENT




CHANNEL SERVICES >>