Slashdot Mirror


MS Excel exploit on auction

geo_2677 writes "Someone had put up for auction on eBay the details of an exploit in Microsoft Excel according to a recent article on Securityfocus. According to the article Microsoft has confirmed that this vulnerability exists, but in the meantime the original listing on eBay has been pulled. " The now pulled auction, but it does appear that Microsoft has confirmed the vulnerability in an eweek article.

9 of 179 comments (clear)

  1. More information and a few questions: by TripMaster+Monkey · · Score: 5, Interesting

    First, in the interest of stimulating more informed discusion, here is some more information concerning the auction:
    • The actual article on SecurityFocus (not the abbreviated discussion article referenced in TFS).
    • The full text of the auction, courtesy of the good folks at the OSVDB blog.
    • The screenie of the actual eBay auction, again courtesy of OSVDB.

    From the auction text:
    The lot: One 0-day Microsoft Excel Vulnerability

    Up for sale is one (1) brand new vulnerability in the Microsoft Excel application. The vulnerability was discovered on December 6th 2005, all the details were submitted to Microsoft, and the reply was received indicating that they may start working on it. It can be assumed that no patch addressing this vulnerability will be available within the next few months. So, since I was unable to find any use for this by-product of Microsoft developers, it is now available for you at the low starting price of $0.01 (a fair value estimation for any Microsoft product).

    A percentage of this sale will be contributed to various open-source projects.
    Second, two questions:
    1. As the seller did in fact report this vulerability to Microsoft first, would his subsequent attempt to call attention to the vulnerability by posting it for auction on eBay be considered 'irresponsible'?
    2. Exactly which eBay rule did this auction break?


    Discuss.
    --
    ____

    ~ |rip/\/\aster /\/\onkey

    1. Re:More information and a few questions: by generic-man · · Score: 5, Funny

      The seller violated eBay's policy of Don't Fuck With Microsoft.

      --
      For more information, click here.
    2. Re:More information and a few questions: by Ph33r+th3+g(O)at · · Score: 5, Insightful

      You mean a security researcher or corporate security officer couldn't have used that information? People who believe that the suppression of information is okay because it could be misused are heading down a dark road, the price of return from which will have to be paid in blood someday by a future generation.

      --
      I too have felt the cold finger of injustice.
    3. Re:More information and a few questions: by sh00z · · Score: 5, Interesting
      2. Exactly which eBay rule did this auction break?
      Probably the restriction on downloadable media, because the seller stated intent to e-mail the file, but did not explicitly state that he is the copyright owner of the electronic file(s) for sale. It seems that M$ would have had a court injunciton to prove criminal intent.
    4. Re:More information and a few questions: by RaymondInFinland · · Score: 5, Insightful

      No, criminal profiteering. The only type of person who could make use of the information apart from Microsoft is a criminal.
      What about the system administrator trying to secure his networks? There are plenty of legitimate reasons why someone would want to know exactly what the vulnerability is so they are able to stop people from using it.

      EBay has a right and a duty to stop trade in vulnerabilities same as they have a right and duty to stop trade in any other illegal material.
      So vulnerabilities are now illegal material? Better call the cops and the feds to shut down Microsoft because they seem to be producing a lot of them.

      This is not 'full disclosure', its selling information to the criminals.
      Wouldn't that depend of the person who would have won the auction? See also point 1).

  2. What was the grounds for pulling the auction? by Ph33r+th3+g(O)at · · Score: 5, Insightful

    eBay is infested with public domain repackagers and sellers of "information" that they seem to do nothing about. But if Microsoft doesn't like an auction, it's gone, apparently.

    --
    I too have felt the cold finger of injustice.
  3. Heh... by the_skywise · · Score: 5, Funny

    Now THAT'S capitalism!

    (Or at least a good demonstration of Ferengi behavior...)

  4. Bad auction by mrRay720 · · Score: 5, Insightful

    Looking at the motivation this guy has, I can't really see how it can be good.

    So, it was submitted to Microsoft on the 6th, and since then he's recieved a reply stating they'll probably be working on a fix. That was LESS THAN A WEEK AGO. Releasing vulnerabilities is something that, IMO, should only be done if (a) there is some specific need for everyone to know about it right now, or (b) requests for fixes have fallen on deaf ears or otherwise failed for an extended period of time.
    This meets neither of those criteria.

    - looking to make a profit from releasing details of a vulterability
    - phrasing the auction in a way that makes it clear he wants the buyer to do something bad - "It can be assumed that no patch addressing this vulnerability will be available within the next few months"

    Sounds to me more like some dumb little script kiddy that got lucky finding a small hole, but doesn't have the ability to do anything with it. Working from an illogical hatred of MS he's trying to get someone else to unleash a virus on the world on his behalf.

    What a great guy.

  5. I Don't think you read the RTFA by djdavetrouble · · Score: 5, Informative

    and shame on the moderators as well. This is obviously either a publicity stunt or this guy is just
    having some fun and saying fuck you M$ in a very public arena. Did you read this hilarious part?

    Special offers:
    Microsoft representatives get 10% off the final price. To qualify, you MUST provide @microsoft.com e-mail address and MUST mention discount code LINUXRULZ during checkout.


    parent says: phrasing the auction in a way that makes it clear he wants the buyer to do something bad

    No, specifically forbidden by auction text, with no winks or smilies or anything ironic.
    Your bid indicates that you agree to the following:
    1. You may not use this information for malicious or illegal purposes. The information you receive is for educational and
    research purposes only.
    2. The seller reserves the right to refuse delivery to anyone (a full refund will be issued).
    3. The seller will accept no responsibility for anything you do with this information.
    4. The seller cannot be held liable under any circumstances.
    5. Absolutely no refunds will be provided except for the reason mentioned above.


    Parent says: Looking at the motivation this guy has, I can't really see how it can be good.

    It calls to attention that a critical vulnerability will go unpatched for months after it has been properly disclosed. That is the way that it can be good.

    --
    music lover since 1969