<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments for Scorptek • GMNews</title>
	<atom:link href="http://gmnews.scorptek.net/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://gmnews.scorptek.net</link>
	<description>powered by Scorptek</description>
	<pubDate>Sat, 22 Nov 2008 13:28:33 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on InstantPlay Exploit Published by James Rhodes</title>
		<link>http://gmnews.scorptek.net/2008/11/21/instantplay-exploit-published/#comment-9142</link>
		<dc:creator>James Rhodes</dc:creator>
		<pubDate>Sat, 22 Nov 2008 10:37:26 +0000</pubDate>
		<guid isPermaLink="false">http://gmnews.wordpress.com/?p=557#comment-9142</guid>
		<description>Maybe you don't understand.  At no point did I give people the ability to recreate and execute the vunerability.  I posted the proof of concept and created a discussion describing it.</description>
		<content:encoded><![CDATA[<p>Maybe you don&#8217;t understand.  At no point did I give people the ability to recreate and execute the vunerability.  I posted the proof of concept and created a discussion describing it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on InstantPlay Exploit Published by NakedPaulToast</title>
		<link>http://gmnews.scorptek.net/2008/11/21/instantplay-exploit-published/#comment-9141</link>
		<dc:creator>NakedPaulToast</dc:creator>
		<pubDate>Sat, 22 Nov 2008 03:42:11 +0000</pubDate>
		<guid isPermaLink="false">http://gmnews.wordpress.com/?p=557#comment-9141</guid>
		<description>"The time they take to fix it will tell users how trustworthy they are as a company." 

How quickly they respond, has nothing to with trustworthiness.

@James Rhodes
First off, excellent work.

I was thinking of tearing you a new one last night, but I thought the topic to important, and didn't want o hijack it.

My issue was not that you discovered the vulnerability, but how you released it into the wild. I'm a firm believer in full disclosure, but not by actually creating and releasing an exploit.

I think you should have created your proof of concept, even created a discussion describing it. But not actually provided the means to individuals recreate and execute the vulnerability to a partially unsuspecting public.

Depending on the responsiveness of YYGs, then possibly release if they feel it is unimportant. When vulnerabilities are discovered, it's important that vendors have a chance to protect themselves and their customers first.

Anyway, wonderful work.</description>
		<content:encoded><![CDATA[<p>&#8220;The time they take to fix it will tell users how trustworthy they are as a company.&#8221; </p>
<p>How quickly they respond, has nothing to with trustworthiness.</p>
<p>@James Rhodes<br />
First off, excellent work.</p>
<p>I was thinking of tearing you a new one last night, but I thought the topic to important, and didn&#8217;t want o hijack it.</p>
<p>My issue was not that you discovered the vulnerability, but how you released it into the wild. I&#8217;m a firm believer in full disclosure, but not by actually creating and releasing an exploit.</p>
<p>I think you should have created your proof of concept, even created a discussion describing it. But not actually provided the means to individuals recreate and execute the vulnerability to a partially unsuspecting public.</p>
<p>Depending on the responsiveness of YYGs, then possibly release if they feel it is unimportant. When vulnerabilities are discovered, it&#8217;s important that vendors have a chance to protect themselves and their customers first.</p>
<p>Anyway, wonderful work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on InstantPlay Exploit Published by infinitously</title>
		<link>http://gmnews.scorptek.net/2008/11/21/instantplay-exploit-published/#comment-9140</link>
		<dc:creator>infinitously</dc:creator>
		<pubDate>Sat, 22 Nov 2008 02:08:43 +0000</pubDate>
		<guid isPermaLink="false">http://gmnews.wordpress.com/?p=557#comment-9140</guid>
		<description>Can't you include any type of file- including a standard .exe file- in the program and run it when the games starts?</description>
		<content:encoded><![CDATA[<p>Can&#8217;t you include any type of file- including a standard .exe file- in the program and run it when the games starts?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on InstantPlay Exploit Published by James Rhodes</title>
		<link>http://gmnews.scorptek.net/2008/11/21/instantplay-exploit-published/#comment-9139</link>
		<dc:creator>James Rhodes</dc:creator>
		<pubDate>Fri, 21 Nov 2008 23:24:23 +0000</pubDate>
		<guid isPermaLink="false">http://gmnews.wordpress.com/?p=557#comment-9139</guid>
		<description>* Yes, but standard EXE files are not made instant playable.</description>
		<content:encoded><![CDATA[<p>* Yes, but standard EXE files are not made instant playable.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on InstantPlay Exploit Published by James Rhodes</title>
		<link>http://gmnews.scorptek.net/2008/11/21/instantplay-exploit-published/#comment-9138</link>
		<dc:creator>James Rhodes</dc:creator>
		<pubDate>Fri, 21 Nov 2008 23:23:57 +0000</pubDate>
		<guid isPermaLink="false">http://gmnews.wordpress.com/?p=557#comment-9138</guid>
		<description>Yes, but standard EXE files are made instant playable.</description>
		<content:encoded><![CDATA[<p>Yes, but standard EXE files are made instant playable.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on InstantPlay Exploit Published by Blijbol</title>
		<link>http://gmnews.scorptek.net/2008/11/21/instantplay-exploit-published/#comment-9137</link>
		<dc:creator>Blijbol</dc:creator>
		<pubDate>Fri, 21 Nov 2008 21:42:52 +0000</pubDate>
		<guid isPermaLink="false">http://gmnews.wordpress.com/?p=557#comment-9137</guid>
		<description>Can't an EXE file being executed do such things anyway?</description>
		<content:encoded><![CDATA[<p>Can&#8217;t an EXE file being executed do such things anyway?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on InstantPlay Exploit Published by James Rhodes</title>
		<link>http://gmnews.scorptek.net/2008/11/21/instantplay-exploit-published/#comment-9136</link>
		<dc:creator>James Rhodes</dc:creator>
		<pubDate>Fri, 21 Nov 2008 21:38:21 +0000</pubDate>
		<guid isPermaLink="false">http://gmnews.wordpress.com/?p=557#comment-9136</guid>
		<description>@Joerdgs,

I was receiving harsh critism for finding the exploit at the GMC, so KC LC saved me from a bashing and hid the topic so that only the YoYoGames staff would see it.</description>
		<content:encoded><![CDATA[<p>@Joerdgs,</p>
<p>I was receiving harsh critism for finding the exploit at the GMC, so KC LC saved me from a bashing and hid the topic so that only the YoYoGames staff would see it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on InstantPlay Exploit Published by Luís Reis</title>
		<link>http://gmnews.scorptek.net/2008/11/21/instantplay-exploit-published/#comment-9135</link>
		<dc:creator>Luís Reis</dc:creator>
		<pubDate>Fri, 21 Nov 2008 20:11:52 +0000</pubDate>
		<guid isPermaLink="false">http://gmnews.wordpress.com/?p=557#comment-9135</guid>
		<description>"It should be interesting to see how long YoyoGames takes to patch this, considering the seriousness of the vulnerability."

Truly an opportunity to test YoYoGames. I don't think they have had such vulnerabilities in the past. The time they take to fix it will tell users how trustworthy they are as a company.</description>
		<content:encoded><![CDATA[<p>&#8220;It should be interesting to see how long YoyoGames takes to patch this, considering the seriousness of the vulnerability.&#8221;</p>
<p>Truly an opportunity to test YoYoGames. I don&#8217;t think they have had such vulnerabilities in the past. The time they take to fix it will tell users how trustworthy they are as a company.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on InstantPlay Exploit Published by Caniac</title>
		<link>http://gmnews.scorptek.net/2008/11/21/instantplay-exploit-published/#comment-9134</link>
		<dc:creator>Caniac</dc:creator>
		<pubDate>Fri, 21 Nov 2008 18:00:02 +0000</pubDate>
		<guid isPermaLink="false">http://gmnews.wordpress.com/?p=557#comment-9134</guid>
		<description>LOL, that is hilarious!
its about time that somone showed yoyo just how insecure their instant play is.</description>
		<content:encoded><![CDATA[<p>LOL, that is hilarious!<br />
its about time that somone showed yoyo just how insecure their instant play is.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on InstantPlay Exploit Published by Rusky</title>
		<link>http://gmnews.scorptek.net/2008/11/21/instantplay-exploit-published/#comment-9133</link>
		<dc:creator>Rusky</dc:creator>
		<pubDate>Fri, 21 Nov 2008 12:24:53 +0000</pubDate>
		<guid isPermaLink="false">http://gmnews.wordpress.com/?p=557#comment-9133</guid>
		<description>That's a stupid main reason.

But anyway, post the explanation somewhere besides the GMC so I don't have to decompile it and figure it out :P</description>
		<content:encoded><![CDATA[<p>That&#8217;s a stupid main reason.</p>
<p>But anyway, post the explanation somewhere besides the GMC so I don&#8217;t have to decompile it and figure it out <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
