Frenchman fined for exploit-posting exploits

By
Follow google news

A Frenchman was found guilty in a Paris court yesterday for publishing exploit code of a company's anti-virus product.

Guillaume Tena, received a suspended fine of €5,000 for publishing both a vulnerability and a proof of concept virus on his website.


Tena, a Harvard University researcher, posted exploits online that pointed to holes in French anti-virus firm Tegam's Viguard anti-virus. Tena justified his actions in an online diary.

"In March 2002, I published on my website a long analysis about this software. This webpage showed how the program worked, demonstrated a few security flaws, and some tests with real viruses," Tena wrote. "I showed that, unlike the advertizing claimed, this software didn't detect and stopped(sic) 100% of viruses."

The suspended fine means that Tena will face further action should he ever repeat his offence.

"To use an analogy, it's a little bit as if Ford was selling cars with defective brakes, if I realized that there was a problem, opened the hood and took a few pictures to prove it, and published everything on my website. And then Ford filed a complaint against me for that," Tena complained.

Tegam is now pursuing a civil case which could see Tena face a fine of up to €900,000.

The time between exploits being published and viruses exploiting those exploits appearing in the wild is approaching hours. In November SC reported virus writers approaching zero day exploits.

www.viguard.com

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Dead cars tell tales by storing data that's never wiped

Dead cars tell tales by storing data that's never wiped

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

AI-boosted hacks with Anthropic’s Mythos could have dire consequences for banks

AI-boosted hacks with Anthropic’s Mythos could have dire consequences for banks

Cloud deployment firm Vercel breached, advises secrets rotation

Cloud deployment firm Vercel breached, advises secrets rotation

Log In

  |  Forgot your password?