Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Slashdot Log In

Log In

[ Create a new account ]

VeriSign Puts Flaw Bounty on Vista and IE7

Posted by samzenpus on Wed Jan 10, 2007 06:16 PM
from the bug-money dept.
rchris1172 writes "VeriSign's iDefense Labs has placed an $8,000 bounty on remote code execution holes in Windows Vista and Internet Explorer 7. As part of its its controversial pay-for-flaw VCP (Vulnerability Contributor Program), iDefense said it will pay the reward for each submitted vulnerability that allows an attacker to remotely exploit and execute arbitrary code on either of the two Microsoft products. In addition to the $8,000 award for the flaw, iDefense will pay between $2,000 and $4,000 for working exploit code that exploits the submitted vulnerability."
This discussion has been archived. No new comments can be posted.
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • Only 8k? (Score:5, Interesting)

    by Anonymous Coward on Wednesday January 10 2007, @06:21PM (#17548402)
    Only 8k for bugs which go on the market for 15-100k each exploit? Surely you jest, no self righteous will go for such a scam.
  • The ping of death (Score:1, Interesting)

    by compandsci (1045690) on Wednesday January 10 2007, @06:23PM (#17548428)
    (http://compandsci.blogspot.com/)
    I remember that win 95 had a flaw that allowed anyone to DoS the computer over the network.
    This was hilarious to use at the LAN parties.

    It would be good fun if someone found a similar flaw with vista and wrote a Linux client for it :)
    • 1 reply beneath your current threshold.
  • 1. Put bounty of $8000 on bugs for Vista and IE7.

    2. Get friend to go work at MSFT.

    .

    4. PROFIT!
  • by Odiumjunkie (926074) on Wednesday January 10 2007, @06:25PM (#17548456)
    use insider knowledge of their own software to extract trillions of dollars from VeriSign!

    Come on, no-one actually thought people could use MS software for anything else did they?
  • Effective... (Score:5, Insightful)

    by clifgriffin (676199) on Wednesday January 10 2007, @06:30PM (#17548508)
    (http://clifgriffin.com/)
    While others may scoff at 8,000 dollars, people are spending hundreds of hours on projects that are bringing in much less if anything. This is a good way to give people healthy motivation and reveal vulnerabilities early...before they make headlines.

    So, not so stupid. Unlike most of the posts on this article so far.
    • Re: Effective by TobyRush (Score:1) Wednesday January 10 2007, @06:48PM
    • Re:Effective... (Score:5, Insightful)

      by LoudMusic (199347) on Wednesday January 10 2007, @06:56PM (#17548864)

      While others may scoff at 8,000 dollars, people are spending hundreds of hours on projects that are bringing in much less if anything. This is a good way to give people healthy motivation and reveal vulnerabilities early...before they make headlines.

      So, not so stupid. Unlike most of the posts on this article so far.
      Except that not everyone, in fact very few, will eventually be given a reward while hundreds of thousands of individuals spend possibly hundreds of hours each searching for flaws.

      What it's really doing is getting those hundreds of thousands of individuals to do someone else's (Microsoft's) job for them for damn near free.
      [ Parent ]
    • 1 reply beneath your current threshold.
  • Moar money (Score:5, Funny)

    by zecg (521666) on Wednesday January 10 2007, @06:32PM (#17548528)
    "In addition to the $8,000 award for the flaw, iDefense will pay between $2,000 and $4,000 for working exploit code that exploits the submitted vulnerability."

    The company spokesman also added they'll double the bounty if the submitter already used the exploit to build a botnet and triple it if promises to use it to send a metric assload of e-mails with the subject "ha-ha" to everyone@microsoft.com.
    • Re:Moar money by Aminion (Score:1) Wednesday January 10 2007, @08:13PM
  • fix in 1 day?? (Score:1)

    by ganjadude (952775) <`moc.loa' `ta' `1934yollamp'> on Wednesday January 10 2007, @06:34PM (#17548546)
    (http://www.sepica.com/)
    Did microsoft have a change of management already???

    FTA:Microsoft typically frowns on the broker market for flaws in its products. "We do not believe that offering compensation for vulnerability information is the best way [researchers] can help protect customers," the company said during the last iDefense hacking challenge.

    "Microsoft believes that responsible disclosure, which involves making sure that an update is available from software vendors the same day the vulnerability is first broadly known, is the best way to protect the end user," a Microsoft spokesperson, in Redmond, Wash., said at that time.
  • Not going to work (Score:5, Interesting)

    by AngryDad (947591) on Wednesday January 10 2007, @06:35PM (#17548560)
    (Last Journal: Wednesday July 18, @05:14PM)
    iDefense ask you to provide all your background information, names, addressess, telephones, photocopies of IDs, etc. Most people who can find vulnerabilities will not be willing to sacrifice their privacy. When iDefence and alike will only ask for e-mail address to paypal funds to, I'd be first in line to talk to them.

  • Sounds like a low figure (Score:2, Insightful)

    by Hyram Graff (962405) on Wednesday January 10 2007, @06:35PM (#17548564)

    $8000 might sound like a lot until you compare it to the stories we see of vulnerabilities being sold for $50,000 on underground sites. Why should I sell my findings to them for a much smaller amount?

  • by Sciros (986030) on Wednesday January 10 2007, @06:35PM (#17548570)
    $8000 for a bug report seems like a lot but I wonder if Microsoft's QA folks don't end up earning at least as much for any serious bugs they manage to uncover towards the end of development (salary:bugs ratio, that is). And at this point, it should take a very serious amount of effort to uncover a big vulnerability (well, hopefully), perhaps such that $8000 isn't even worth the time for some.

    By the way it would not be that great of an idea for MS employees to go around submitting bugs to VeriSign, particularly if they get published and traced back to some feature those employees were working on ;-) So, yeah haha big plot by Microsoft to get billions from VeriSign, but not really. The only people that will profit from this IMO are poor computer hackers or IT folks who somehow happened to be using a buggy feature in Vista during work and noticed it.
  • NOT the best business move! (Score:5, Funny)

    by Arthur Dent '99 (226844) on Wednesday January 10 2007, @06:37PM (#17548594)

    Paying $8000 for each exploitable security flaw in Microsoft products is a quick way to put a company into bankruptcy! I noticed that the bounty only applies to the first six submissions, though, so VeriSign is only out $48000.

    Who else here thinks that VeriSign will then turn around and sell the winning entries to the black market for $50000 each? hehe

  • by andersen (10283) on Wednesday January 10 2007, @06:40PM (#17548636)
    (http://codepoet.org/)
    Pointy Haired Boss: Our goal is to write bug-free software. I'll pay a ten dollar bonus for every bug you find and fix.
    Dilbert: Yahoo!
    Alice: We're rich
    Wally: Yes!!! Yes!!! Yes!!!
    Pointy Haired Boss: I hope this drives the right behavior.
    Wally: I'm gonna write me a new minivan this afternoon!

    http://www.ourlocalstyle.com/images/uploadImages/2 006/05/13/dilbert_bugFixMinivan.gif [ourlocalstyle.com]
  • by QueePWNzor (1044224) on Wednesday January 10 2007, @06:43PM (#17548678)
    (Last Journal: Tuesday February 27 2007, @09:35PM)
    Considering that over half the world will be using those soon, and knowing MS, let's hope that: a. Normal users are too stupid to figure out the bugs that destroy their comps, b.VeriSign is very, very, rich, and c. We remember this opportunity, because if you're reading Slashdot, you should be able to detect and report all flaws you come about (in Vista, 500,000,000 per second.) Don't be lazy!

    Actually, be lazy. I want to cash in.
  • Oh, please (Score:2, Insightful)

    by lawrenlives (991376) on Wednesday January 10 2007, @06:57PM (#17548872)
    I'd like to think not everyone involved in the "field" is a scumbag criminal in cahoots with the Russian mafia. Go ahead, prove me wrong! Despite the seemingly faceless nature of corporations, it's always human beings like you and me that get screwed in the end.
  • by SeaFox (739806) on Wednesday January 10 2007, @06:59PM (#17548890)
    I think Microsoft should be the one who has to pay for the venerabilities. Maybe then they will have a little bit more of an incentive to produce secure code. The usual market force for this sort of thing (customers will drop the vendor for one who supplies the more secure solution) does not apply when you have a monopoly.
  • by TastyWheat (302413) on Wednesday January 10 2007, @06:59PM (#17548896)
    And get paid for it??

    Hax0r1ng is getting better all the time!
    And they said we were just a bunch of internet hooligans.

    muahahhaha
    • 1 reply beneath your current threshold.
  • Chump Change (Score:2)

    by pestilence669 (823950) on Wednesday January 10 2007, @07:09PM (#17549016)
    Don't they know how much money you can make blasting Cialis advertisements on random people's computers? AdWare is much more lucrative. They need to step that bounty up. Remote execution exploits for Windows are like virtual gold.
  • Legal? (Score:2)

    by nurb432 (527695) on Wednesday January 10 2007, @07:17PM (#17549100)
    (http://slashdot.org/~nurb432/ | Last Journal: Friday August 27 2004, @03:24PM)
    Is it even legal to look for possible holes anymore?

    With all the legal issues and suits flying around, id be sort of afraid to admit i knew something.
  • Greedo shot first (Score:2)

    by dangitman (862676) on Wednesday January 10 2007, @07:20PM (#17549144)
    A: "I'm a bug hunter"

    B: "You exterminate insects, then?"

    A: "Sort of. It involves looking in lots of holes. That's all I can say right now. I'm late for a meeting with Jabba."

  • Pfft (Score:3, Insightful)

    by Tom (822) on Wednesday January 10 2007, @08:07PM (#17549796)
    (http://web.lemuria.org/)
    What a cheap publicity stunt.

    A 0day of this kind is worth at least twice that on the black market, mostly to the botnet creators who are the base of all the spam we get.
    • Re:Pfft by danzona (Score:1) Thursday January 11 2007, @11:48AM
    • 1 reply beneath your current threshold.
  • by JourneyExpertApe (906162) on Wednesday January 10 2007, @08:51PM (#17550384)
    ...to offset the winner's legal expenses. Do you get an additional prize if you are actually convicted?
  • In other news... (Score:2, Funny)

    ...both Apple and Cisco are suing VeriSign for the use of iDefense in the name of their labs. Apple claims that it dilutes their brand identity, and Cisco claims that they've been selling "defense" hardware with the "i" trademark for years!

  • ..like for instance as a bribe to the ad-ware industry. It could seize development of ad-ware for hours, if not days!
  • Microsoft (Score:1)

    by endianx (1006895) on Thursday January 11 2007, @09:29AM (#17555994)
    (http://www.ronpaul2008.com/)
    Why is a 3rd party doing this, instead of Microsoft? If they have such confidence in the security of their new software, I would think they would be open to such a thing. Seems like a win/win to me. Either they get big media attention for having secure software, or they get attention for having bugs, but they were fixed, and it looks like Microsoft was actually doing something to make that happen.
  • Dear Verisign, (Score:2)

    by muckdog (607284) on Thursday January 11 2007, @11:04AM (#17557244)
    (http://www.jaysweb.net/)
    Attached is working exploits for 832 different new vulnerabilities in Microsoft Vista and IE7. Please send me my check for $8,320,000. Sincerely, Bob Smith Sr. Software Engineer bsmith@microsoft.com
  • by jo42 (227475) on Thursday January 11 2007, @03:04PM (#17561846)
    (http://127.0.0.42/)
    URLs of the format:

    ftp://account:password@ftp.example.com
    no longer appear to work in IE7. Fargh!
  • Re:Four Steps to Profit (Score:5, Informative)

    by creimer (824291) on Wednesday January 10 2007, @06:33PM (#17548540)
    (http://www.creimer.ws/ | Last Journal: Friday January 26 2007, @12:40PM)
    Didn't you read the fine print... current/former Microsoft employees not allowed. Otherwise, every anonymous coward at Microsoft would get the same idea and sabotage Vista/IE7 to collect the reward. Crime isn't supposed to pay if you're non-monopolist!
    [ Parent ]
  • 5 replies beneath your current threshold.