<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: hps]]></title>
    <link>http://securityratty.com/tag/hps</link>
    <description></description>
    <pubDate>Wed, 13 Feb 2008 16:12:03 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Selling 0day Exploit Code]]></title>
      <link>http://securityratty.com/article/6fecfbd98ce0e43927152713256b4ea0</link>
      <guid>http://securityratty.com/article/6fecfbd98ce0e43927152713256b4ea0</guid>
      <description><![CDATA[We all know it happens, but it is rarely exposed as clearly as Adam Pennenberg did in his article for Fast Company, The Black Market Code Industry . It turns out that this 0day seller was an HP...]]></description>
      <content:encoded><![CDATA[<p>We all know it happens, but it is rarely exposed as clearly as Adam Pennenberg did in his article for Fast Company, <a href="http://www.fastcompany.com/magazine/127/nexttech-fear-of-a-black-hat.html">The Black Market Code Industry</a>.  It turns out that this 0day seller was an HP employee:</p>
<blockquote><p>According to the consultant who snared Marester, his quarry&#8217;s skills appear quite sophisticated. His wares, if they performed as advertised, could help a hacker take down machines running that particular software anywhere in the world. His real name is Steve Rigano; he&#8217;s a self-employed network consultant from Grenoble, France, who works full time at HP, where he is listed in the switchboard and maintains an hp.com email address. He told me that he saw nothing wrong with offering tools and techniques that targeted the company providing his paycheck.</p>
<p>A self-taught hacker, Rigano says he discovered the vulnerabilities and coded the exploits on his own time, which he says is none of HP&#8217;s business. &#8220;I have the right to sell what I want,&#8221; he says. He told me he attracted mostly Chinese and Russian buyers, but claimed he never found takers for the HP or SAP &#8220;vulns&#8221; and exploits. He said he stopped selling black-market code in January but didn&#8217;t explain why.</p></blockquote>
<p>Most security companies I have been acquainted with frown on this type of activity, as I am sure HP has.  It&#8217;s hard for them to sell security products and services when their employees are selling the very tools the company is purportedly defending against.</p>
]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 14:55:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast company">fast company</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/consultant">consultant</category>
      <category domain="http://securityratty.com/tag/rigano">rigano</category>
      <category domain="http://securityratty.com/tag/steve rigano">steve rigano</category>
      <category domain="http://securityratty.com/tag/self-taught hacker">self-taught hacker</category>
      <category domain="http://securityratty.com/tag/network consultant">network consultant</category>
      <category domain="http://securityratty.com/tag/hacker">hacker</category>
      <category domain="http://securityratty.com/tag/sap vulns">sap vulns</category>
      <source url="http://www.veracode.com/blog/?p=116">Selling 0day Exploit Code</source>
    </item>
    <item>
      <title><![CDATA[Who Are the Information Security Experts?]]></title>
      <link>http://securityratty.com/article/f4f9c8ed56a1b5e4d34585b0c64fb0e0</link>
      <guid>http://securityratty.com/article/f4f9c8ed56a1b5e4d34585b0c64fb0e0</guid>
      <description><![CDATA[Recently an executive at HP claimed that his company now employs 9 out of the top 11 security people due to HPs acquisition of SPI Dynamics
Nine out of the worlds top 11 security hackers came to HP...]]></description>
      <content:encoded><![CDATA[<p>Recently an <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=206105145">executive at HP claimed</a> that his company now employs 9 out of the top 11 security people due to HP&#8217;s acquisition of SPI Dynamics:</p>
<blockquote><p>
&#8220;Nine out of the world&#8217;s top 11 security hackers came to HP through the SPI Dynamics acquisition, he boasts, although it&#8217;s not immediately clear who ranked those top 11.&#8221;<br />
-  Mark Potts, CTO of Software, Hewlett-Packard</p>
</blockquote>
<p>Now eWeek has produced a list of the <a href="http://www.eweek.com/c/a/Security/The-15-Most-Influential-People-in-Security-Today/">15 most influential people in security today</a>. Here is the quick non-multimedia version:</p>
<ol>
<li>Tavis Ormandy, Google Security Team</li>
<li>Ivan Krstic, One Laptop Per Child</li>
<li>Chris Paget, IOActive</li>
<li>Bunnie Huang, Bunnie Studios</li>
<li>Michal Zalewski, Google</li>
<li>Window Snyder</li>
<li>The MOAB Hackers</li>
<li>Dino Dai Zovi</li>
<li>Michael Howard, Microsoft</li>
<li>HD Moore, Metasploit</li>
<li>Dave Aitel, Immunity</li>
<li>Bronwen Matthews, Microsoft</li>
<li>John Pescatore, Gartner</li>
<li>Rob Thomas and Team Cymru</li>
<li>Stefan Esser, Hardened PHP Project</li>
</ol>
<p></p>
<p>I don&#8217;t see any SPI Dynamics or HP people on this arguably less biased list.  I do see 3 of my former collegues from @stake: Dave Aitel, Dino Dai Zovi, and Window Snyder.  Seeing that giants Microsoft and Google only got 2 each on the list and @stake has 3 it lends credence that <a href="http://searchsecurity.techtarget.com/news/interview/0,289202,sid14_gci1296604,00.html">@stake was the place to be</a> for hard core security people.</p>
<p>Wikipedia has a nice large list of <a href="http://en.wikipedia.org/wiki/Category:Computer_security_specialists">computer security specialists</a>.</p>
]]></content:encoded>
      <pubDate>Wed, 13 Feb 2008 16:12:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security hackers">security hackers</category>
      <category domain="http://securityratty.com/tag/computer security specialists">computer security specialists</category>
      <category domain="http://securityratty.com/tag/security people due">security people due</category>
      <category domain="http://securityratty.com/tag/spi dynamics">spi dynamics</category>
      <category domain="http://securityratty.com/tag/spi dynamics acquisition">spi dynamics acquisition</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/google security team">google security team</category>
      <category domain="http://securityratty.com/tag/dino dai zovi">dino dai zovi</category>
      <source url="http://www.veracode.com/blog/?p=79">Who Are the Information Security Experts?</source>
    </item>
  </channel>
</rss>
