<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in Did IDG Bet $1,000 That Acunetix Can&amp;#8217;t Steal Credit Cards From Random Websites?</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Tue, 20 Feb 2007 06:46:19 -0000</lastBuildDate><item><title>Re: Did IDG Bet $1,000 That Acunetix Can&amp;#8217;t Steal Credit Cards From Random Websites?</title><link>http://www.matasano.com/log/699/did-idg-bet-1000-that-acunetix-cant-steal-credit-cards-from-random-websites/#comment-2321582</link><description>Did anyone realise that Network World deliberately removed postings of Acunetix from its website?&lt;br&gt;&lt;br&gt;True they are a vendor but isn't this beyond journalism, our right to know what is truely happening and the constitutional right to free speech?&lt;br&gt;&lt;br&gt;Network World have lost a loyal customer and Acunetix have gained a new one!&lt;br&gt;&lt;br&gt;&lt;a href="http://www.acunetix.com/news/acunetix_reveals_data.htm" rel="nofollow"&gt;http://www.acunetix.com/news/acunetix_reveals_d...&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Tibbs Jameson</dc:creator><pubDate>Tue, 20 Feb 2007 06:46:19 -0000</pubDate></item><item><title>Re: Did IDG Bet $1,000 That Acunetix Can&amp;#8217;t Steal Credit Cards From Random Websites?</title><link>http://www.matasano.com/log/699/did-idg-bet-1000-that-acunetix-cant-steal-credit-cards-from-random-websites/#comment-2321581</link><description>If Acunetix doesn't win, can I get 1k if I binary patch it to find the required criteria?  I don't use web application vulnerability scanners, but I know for certain that it is capable of finding this sort of information very easily.  I have seen plenty of these exact findings from people using SPI and Appscan...&lt;br&gt;&lt;br&gt;If Acunetix does win, I suggest they call the FCC and have them fine IDG to a tune of a few hundred thousand to million dollars for allowing personal information to be stolen from their website.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">dre</dc:creator><pubDate>Wed, 14 Feb 2007 19:32:10 -0000</pubDate></item><item><title>Re: Did IDG Bet $1,000 That Acunetix Can&amp;#8217;t Steal Credit Cards From Random Websites?</title><link>http://www.matasano.com/log/699/did-idg-bet-1000-that-acunetix-cant-steal-credit-cards-from-random-websites/#comment-2321580</link><description>I think it is actually worse than that.  While I am sure they were just loose with language, by offering money to have Acunetix break into someone's website to retrieve credit card information, I am reasonably sure they  have committed an illegal act themselves.  Of course, I am not a lawyer...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave G.</dc:creator><pubDate>Wed, 14 Feb 2007 14:48:35 -0000</pubDate></item><item><title>Re: Did IDG Bet $1,000 That Acunetix Can&amp;#8217;t Steal Credit Cards From Random Websites?</title><link>http://www.matasano.com/log/699/did-idg-bet-1000-that-acunetix-cant-steal-credit-cards-from-random-websites/#comment-2321579</link><description>"On the other hand, even a stopped clock, etc, etc: most people in the trenches would say 70% is a lowball estimate."&lt;br&gt;&lt;br&gt;My sentiments exactly.  &lt;br&gt;&lt;br&gt;I happen to agree with the point Snyder is trying to make, which is that there's a disconnect between scanner findings, app-level vulnerabilities, and actual data booty - a point that is missing from Acunetix marketing stunt for obvious reasons.  But in trying to stunt on their stunt, he's let himself get backed into a corner, and the outlook's not good.  Either he backs off, or he and McNamara are going to be in hot water with IDG's CISO and legal team.  This will be a fun one to watch.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">PaulM</dc:creator><pubDate>Wed, 14 Feb 2007 11:39:14 -0000</pubDate></item></channel></rss>