Top Tech News

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Product Reviews for Tech Leaders
Tuesday, February 9th 
Home
Network Security
Microsoft/Windows
Linux/Open Source
Apple/Macintosh
Wireless Tech
World Wide Web
Tech Trends
Data Storage
Software
Hardware
Communications
Spam & Hackers
Chips & Processors
E-Business
Personal Tech
 

Advertisement
Data Security

Excel Security Flaw Yanked from eBay

Excel Security Flaw Yanked from eBay
December 12, 2005 9:10AM

Bookmark and Share
"EBay did the right thing in taking it down so quickly," said Graham Cluley, senior technology consultant at Sophos. "Even if it's not legitimate, it's certainly not funny to see flaws up for sale."


Auction site eBay has stopped an auction of a seller trying to hawk information about an alleged software exploit in Microsoft Relevant Products/Services's Excel program.

The flaw is supposedly so severe that it gives hackers the ability to control a computer remotely by exploiting the flaw on a computer that has Excel installed.

EBay noted that the listing was reviewed immediately after being put online, and pulled shortly after.

Although the seller is not breaking the law, the listing did violate one of the site's policies, stating that nothing will be sold that promotes illegal activity.

Not for Sale

The listing stated that the vulnerability was discovered on December 6, and that details of the flaw had already been submitted to Microsoft but that the software company had not yet issued a patch.

The seller wrote that the flaw was available at the low starting price of one penny, with an aside that the price should be considered "a fair value estimation for any Microsoft product."

According to the listing, the winning bidder would have received two Excel documents, with one modified to demonstrate the vulnerability. The seller did note, "It is up to you what to do with it, but you may not use it for malicious purposes."

"EBay did the right thing in taking it down so quickly," said Graham Cluley, senior technology consultant at Sophos. "Even if it's not legitimate, it's certainly not funny to see flaws up for sale."

Humor Less

Although it is possible that the flaw exists, and that the seller did report it properly to Microsoft, it is far more likely that the listing was a joke, said Cluley.

"It's hard to know if there's actually a real flaw, because it was taken down," he said. "But it's probably someone either trying to get attention or who needs a busier social life."

In general, Cluley does not think that this attempted eBay sale will represent the birth of a trend, given how the hacker community operates.

"You can usually pick up your flaws for free," he noted. "There are mailing lists where people give example of code and discuss flaws."

Advertisement



 Data Security
1. China Busted Hacker-Training Site
2. FBI Tackles Haiti-Relief Scams
3. Patch Tuesday Will Tie MS Record
4. Google Apps Controls Mobile Devices
5. Torrent Traps Used To Harvest Logins


advertisement


 Most Popular Articles
1. iPhone Loses Global Market Share as Rivals Advance
2. Lessons To Learn from a Year of Big Data Breaches
3. New Sony Ericsson Aspen Handset Uses Windows Mobile
4. Apple Bans Location-Based Ads for iPhone Apps
5. EPIC Objects To Google-NSA Cyber Partnership


advertisement

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Analysts Expect iPad Price To Drop
  The Dearth of Female Entrepreneurs
  China Busted Hacker-Training Site
  Nook E-Reader Heads to Retail Stores
  Veteran SAP CEO Abruptly Resigns

 Technology Marketplace
Compliance
Stand out from other IS Professionals and increase your earning potential.®).
 
Enterprise Hardware
Now is the best time to buy a new APC Smart-UPS!
HP ProLiant G6 Servers: Perform like a superstar, Save like an accountant www.hp.com
 
Enterprise I.T.
Learn how Microsoft server upgrades can create efficiencies
Stand out from other IS Professionals and increase your earning potential.®).
 
Hardware
Find out why now is the best time to buy a new APC Smart-UPS!
 
Microsoft/Windows
Read about how to add efficiencies with Microsoft Virtualization.
 
Network Security
AT&T Synaptic Compute as a Service. Boost your power on demand.
 
Mobile Enterprise Spotlight

Analysts See iPad Price Drop, with Some Cannibalization
Just weeks before Apple officially rolls out the iPad, financial analysts are making pricing predictions. But could the analysis itself hinder the initial demand for the pricey tablet computer?

Bar Codes Go Mobile, Get Hip Again
For decades, retailers have used patterns of black dots and lines to encode data onto products. Now, bar codes are gaining favor as an easy way for cell-phone users to view ads and other data instantly.

'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.

Advertisement
Enterprise Software Spotlight

Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.

SAP CEO Abruptly Resigns; Co-CEOs Will Take Over
Business-software maker SAP announced an abrupt strategic shift in the corporate suite with Léo Apotheker resigning as CEO, to be replaced by co-CEOs Bill McDermott (left) and Jim Hagemann Snabe (right).

Cybersecurity Vendors Look Hot in 2010
Tech-security companies are poised to become Wall Street darlings this year, thanks in part to Google's tiff with China, which reinforced an already positive outlook for major security vendors.

Advertisement
Navigation
Top Tech News
Home/Top News | Network Security | Microsoft/Windows | Linux/Open Source | Apple/Macintosh | Wireless Tech | World Wide Web
Tech Trends | Data Storage | Software | Hardware | Communications | Spam & Hackers | Chips & Processors
E-Business | Personal Tech
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 Top Tech News. All rights reserved. Article rating technology by Blogowogo.