資料來源 http://securitywatch.eweek.com/exploits_and_attacks/20000_bounty_placed_on_windows_flaws_exploits_1.html

January 15, 2008 1:56 PM

$20,000 Bounty Placed on Windows Flaws, Exploits A private company has placed a $20,000 bounty on exploitable vulnerabilities in Microsoft's Windows operating system, a move that significantly raises the value of software flaw research.

Billed as a Hacker Challenge, the $20,000 "special prize" is being offered by Digital Armaments, one of several companies that pay hackers who agree to give them exclusive rights to advance notification of unpublished vulnerabilities or exploit code.

[ ALSO SEE: VeriSign Offers Hackers $8,000 Bounty on Vista, IE 7 Flaws ]

Digital Armaments said the bounty will be available for each submission that results in an exploitable vulnerability or working exploit against Windows or a Windows Diffuse application. To qualify, the flaw data must include examples and documentation, the company said.

Not much is known about the people behind Digital Armaments. The company's Web site does not include any details about its backers or its whereabouts.

This is not the first high-priced flaw data bounty from Digital Armaments, which previously offered hacking challenges for bugs in the Symbian OS, Oracle Database and VMware.

VeriSign's iDefense VCP (Vulnerability Contributor Program) has also placed a public price tag on flaws and exploits in specific products. In December 2007, the company offered between $8,000 and $12,000 for remote arbitrary code execution holes in these e-mail clients and servers:

  # Microsoft Outlook
  # Mozilla Thunderbird
  # Microsoft Outlook Express
  # Sendmail SMTP daemon
  # Microsoft Exchange Server

In the past, iDefense has offered monetary prizes for holes in Windows Vista and Internet Explorer 7.
arrow
arrow
    全站熱搜
    創作者介紹
    創作者 ivan0914 的頭像
    ivan0914

    I'n Blog 之萬象真藏

    ivan0914 發表在 痞客邦 留言(0) 人氣()