<br><br><div><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">company, and refuse to disclose flaws in commercial software (and our<br>customers appreciate this). We are not in the blackmailing
<br>business... Open source would be free target though (my personal<br>opinion, not our company opinion). Thirdly, we do not build exploits<br>like Dave already pointed out earlier, again from ethical reasons (and<br>because nobody has ever asked us to develop exploits for the found
<br>flaws even if building the exploit would be easy). And last note, we<br>would have no use nor interest for your exploit, nor would we want to<br>even see it due to the related liability issues.</blockquote><div><br><br>
Blackmailing business ? Where did you come up with that ? There is a difference in not wanting to offer any free services to Microsoft and blackmailing it ? If you can't tell the difference between the two, you really don't understand much about the nuances of the field you are trying to get some traction from. However you are always quick to respond to Dave's emails regarding Canvas/Spike etc and inserting your worthless commercial rhetoric, I am for a change offering you to do it like a man ? So can you handle that or will keep being the half-assed corporate mouthpiece ?
<br></div><br><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">So I am sorry I have to decline the offer. You are free to continue<br>hunting for your fame and glory from the remote exploits. I wish you
<br>good luck in the hunt! And I will shut up about our products as I<br>definitely do not even want you to get these tools in your hand. ;)</blockquote><div><br><br>Trust me, I would not have any use for your tool. Like many of your contemporaries, your product is an one big blunder and yet another silly excuse to launch a security company.
<br><br>Also if I was for any fame and glory, don't you think I wouldn't settle for the silly credit in Microsoft advisories like many of eEye's foreign imports ? I am (like any other researcher with enough years of experience under his/her belt) are solely interested in the financial gain, pay me my hourly rate and I don't care if you act like you don't even know me, that's just fine.
<br><br></div><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">I hope you had a chance to visit us at RSA! We are constantly looking<br>for skilled people who wish to start doing more proactive work in
<br>security.</blockquote><div><br><br>Proactive work ? ahaha now thats just crazy funny!<br><br><br>Olef.<br><br></div><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
<br>On Thu, Feb 08, 2007 at 01:22:02PM -0500, <a href="mailto:dailydave-request@lists.immunitysec.com">dailydave-request@lists.immunitysec.com</a> wrote:<br>> Date: Thu, 8 Feb 2007 09:48:36 -0800<br>> From: "Olef Anderson" <
<a href="mailto:olef.anderson@gmail.com">olef.anderson@gmail.com</a>><br>> Subject: Re: [Dailydave] Some Sums<br>> To: <a href="mailto:dailydave@lists.immunitysec.com">dailydave@lists.immunitysec.com</a><br>><br>
> About this whole fuzzer business, how about putting some cold hard cash<br>> where the corporate mouthpiece is at ?<br>> Since obviously you happen to have some VC money, a booth at the RSA floor<br>> is a sign, you can back your claims with real currency. I would love to give
<br>> you the opportunity.<br>><br>> Lets take the latest Microsoft Exchange release (2007) and 2 weeks of your<br>> time running your PROTOS fuzzer. At the end of the 2 weeks if you can find<br>> the existing remote root hole in it, I am offering to pay you the bugs worth
<br>> of $150 000.00. However If you are not successful, I should be payed the<br>> very same amount which in return I shall present you the exploit. From that<br>> point you will be free to coordinate vendors, release advisories whatever it
<br>> takes. Just to clarify a point though, no DoSes are acceptable, should be an<br>> overflow that leads to clear code execution ( the mailing list subscribers<br>> could be the judge of that).<br>><br>> Wouldn't that be nice to prove that you actually know what you are talking
<br>> about ?<br>><br>> On 2/7/07, Ari Takanen <<a href="mailto:ari.takanen@codenomicon.com">ari.takanen@codenomicon.com</a>> wrote:<br>> ><br>> > Hmmm, distantly related to this: Maybe us fuzzer developers should
<br>> > save hashes of some millions of attacks somewhere also, so that we can<br>> > prove our tools were used to find the flaws in the first<br>> > place... Looking at past iDefence disclosures for example, I am
<br>> > beginning to doubt that they reward for publishing flaws instead of<br>> > finding flaws (this is like patent system in Europe which rewards<br>> > first to file, not first to invent)... More and more flaws are found
<br>> > using tools, and pre-packaged attacks. If a flaw is found using a<br>> > product like Codenomicon/PROTOS or CANVAS, I supposed the reward<br>> > should also be paid to the tool developer and not the tool user. ;)
<br>> ><br>> > Tongue-in-the-cheek-greetings,<br>> ><br>> > /Ari<br><br>--<br>-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-<br>Ari Takanen Codenomicon Ltd.<br><a href="mailto:ari.takanen@codenomicon.com">
ari.takanen@codenomicon.com</a> Tutkijantie 4E<br>tel: +358-40 50 67678 FIN-90570 Oulu<br><a href="http://www.codenomicon.com">http://www.codenomicon.com</a> Finland<br>PGP: <a href="http://www.codenomicon.com/codenomicon-key.asc">
http://www.codenomicon.com/codenomicon-key.asc</a><br>-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-<br>_______________________________________________<br>Dailydave mailing list<br><a href="mailto:Dailydave@lists.immunitysec.com">
Dailydave@lists.immunitysec.com</a><br><a href="http://lists.immunitysec.com/mailman/listinfo/dailydave">http://lists.immunitysec.com/mailman/listinfo/dailydave</a><br></blockquote></div><br>