$16,000 Bounty for Sendmail, Apache Zero-Day Flaws 173
Famestay writes "Verisign's iDefense is putting up a $16,000 prize for any hacker who can find a remotely exploitable vulnerability in six critical Internet infrastructure applications. The bounty is for a zero-day code execution hole on the following Internet infrastructure technologies: Apache httpd, Berkeley Internet Name Domain (BIND) daemon, Sendmail SMTP daemon, OpenSSH sshd, Microsoft Internet Information (IIS) Server and Microsoft Exchange Server. 'Immunity founder Dave Aitel, who also purchases flaws and exploits for use in the CANVAS pen testing tool, says its doubtful iDefense will get any submissions from hackers. "It's very hard to exploit [those listed applications]," Aitel said. "IIS 6 hasn't had a public remotely exploitable bug in it. Ever." Several other hackers I spoke to had very much the same message, arguing that $16,000 can never equate to the amount of work/expertise required to find and exploit a hole in the six targeted technologies.'"
IIS and Exchange (Score:1, Funny)
hMMM (Score:3, Funny)
Re:IIS and Exchange (Score:3, Funny)
IIS 6 (Score:5, Funny)
IIS 6 hasn't had a public remotely exploitable bug in it. Ever.
How can that be? IIS is crap! Slashdot tells me so!
Look at me, I'm a hacker (Score:5, Funny)
Re:IIS 6 (Score:5, Funny)
Not to mention ability to convert O2 to CO2... (Score:5, Funny)
True
Re:Exchange (Score:1, Funny)
No need to find a flaw, Ms exchange will crash on it's own.
Re:Not to mention ability to convert O2 to CO2... (Score:3, Funny)
I didn't sign an NDA when i started working for the..... Oh high Vladmir, what are you doing he.....
Re:No, but... (Score:5, Funny)
Yeah, but pimpin' ain't easy.
Re:Tried Google? (Score:4, Funny)
Just to narrow it down, I redid your search with quotes and found 67. But the first one's a blast. It goes to the "w4ck1ng" forum where the thread goes...
"Hello found this exploit: http://www.derkeiler.com/Mailing-Lis...5-04/0436....and the response goes:
"you can not use exe files under unix y0u have to compile it with GCC..."
I *think* IIS is safe from *this* guy...
FYI (Score:5, Funny)
OpenSSH - A service you can install on a Unix system to enable remote admin access for known users.
Sendmail - A service you can install on a Unix system to enable remote admin access for complete strangers.
Hope this helps.....
Re:$16,000 (Score:3, Funny)
It is remote, and it is foolproof.
I want the money.
-nB
The exploit is to take the admins family hostage, demanding whatever code you want to be run in exchange for the family's safety.
Since you are using a phone to control the admin it is a remote exploit.
Have a nice day.
$16k (Score:1, Funny)