Slashdot Log In
VeriSign Puts Flaw Bounty on Vista and IE7
Posted by
samzenpus
on Wed Jan 10, 2007 07:16 PM
from the bug-money dept.
from the bug-money dept.
rchris1172 writes "VeriSign's iDefense Labs has placed an $8,000 bounty on remote code execution holes in Windows Vista and Internet Explorer 7. As part of its its controversial pay-for-flaw VCP (Vulnerability Contributor Program), iDefense said it will pay the reward for each submitted vulnerability that allows an attacker to remotely exploit and execute arbitrary code on either of the two Microsoft products. In addition to the $8,000 award for the flaw, iDefense will pay between $2,000 and $4,000 for working exploit code that exploits the submitted vulnerability."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Only 8k? (Score:5, Interesting)
Re: (Score:3, Insightful)
Then perhaps the simply righteous will step up.
"perhaps the simply righteous will step up" (Score:3, Insightful)
Yeah, and "the righteous" could code, then there wouldn't be any exploits in the first place. 8-).
-- Terry
Re:Wonder what they're really worth? (Score:5, Funny)
Parent
Economics 101 or Why I Love Bounties (Score:4, Funny)
2. Get friend to go work at MSFT.
.
4. PROFIT!
Re:Economics 101 or Why I Love Bounties (Score:5, Insightful)
Parent
Re:Economics 101 or Why I Love Bounties (Score:5, Funny)
O
/|\ <--- you
|
/ \
Parent
Re: (Score:3, Funny)
3. ???
Darn. Guess you get the US $8000 bounty. Now, let's see, that's about 2 Euros, right?
So this is Microsoft's long term profit strategy.. (Score:2)
Come on, no-one actually thought people could use MS software for anything else did they?
Effective... (Score:5, Insightful)
So, not so stupid. Unlike most of the posts on this article so far.
Re:Effective... (Score:5, Insightful)
So, not so stupid. Unlike most of the posts on this article so far.
What it's really doing is getting those hundreds of thousands of individuals to do someone else's (Microsoft's) job for them for damn near free.
Parent
Re: (Score:3, Insightful)
Moar money (Score:5, Funny)
The company spokesman also added they'll double the bounty if the submitter already used the exploit to build a botnet and triple it if promises to use it to send a metric assload of e-mails with the subject "ha-ha" to everyone@microsoft.com.
Not going to work (Score:5, Interesting)
Re: (Score:3, Funny)
You have just won a new Boat!
Please come down to the stadium to pick it up.
Regards
Det. Sgt. Smith
Sounds like a low figure (Score:2, Insightful)
$8000 might sound like a lot until you compare it to the stories we see of vulnerabilities being sold for $50,000 on underground sites. Why should I sell my findings to them for a much smaller amount?
Re: (Score:3, Insightful)
If you can help someone and get payed 8 dollars, or hurt someone and get 50 dollars, what would you do?
I think it's good that there is any compensation at all for white hats who would otherwise recieve no compensation at all for doing the least harmful thing. It would be nice if the rewards for help were on par with harm, but helping is reward in itself for some - and a bit extra reward helps the motivation.
Probably not even all that much money (Score:2)
By the way it would not be that great of an idea for MS employees to go around submitting bugs to VeriSign, particu
NOT the best business move! (Score:5, Funny)
Paying $8000 for each exploitable security flaw in Microsoft products is a quick way to put a company into bankruptcy! I noticed that the bounty only applies to the first six submissions, though, so VeriSign is only out $48000.
Who else here thinks that VeriSign will then turn around and sell the winning entries to the black market for $50000 each? hehe
The law on unintended consequences (Score:5, Funny)
Dilbert: Yahoo!
Alice: We're rich
Wally: Yes!!! Yes!!! Yes!!!
Pointy Haired Boss: I hope this drives the right behavior.
Wally: I'm gonna write me a new minivan this afternoon!
http://www.ourlocalstyle.com/images/uploadImages/
So Now I Can Legally Attempt To Compromise M$ ?? (Score:3, Funny)
Hax0r1ng is getting better all the time!
And they said we were just a bunch of internet hooligans.
muahahhaha
Pfft (Score:3, Insightful)
A 0day of this kind is worth at least twice that on the black market, mostly to the botnet creators who are the base of all the spam we get.
Re:Four Steps to Profit (Score:5, Informative)
Parent
Re: (Score:3, Insightful)
They could turn in bugs they already know about
right, not all are Russian mafia (Score:3, Funny)