Home > Security News > Remote flaw in Vista could earn finder $8,000
Security News:
EMAIL THIS

Remote flaw in Vista could earn finder $8,000

By Dennis Fisher, Executive Editor
10 Jan 2007 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

If the folks at VeriSign Inc.'s iDefense Labs unit have their way, it won't be long before a remotely exploitable flaw in Windows Vista is identified. The group has offered an $8,000 bounty to any researcher who finds such a vulnerability, and will also pay handsomely for a working exploit.

The bounty is part of the company's Quarterly Vulnerability Challenge, an element of its broader Vulnerability Contributor Program through which it pays independent researchers for information on unpublished vulnerabilities and exploits. The practice has drawn fire from a number of software vendors, including Microsoft Corp. and Oracle Corp., but also has been duplicated by other groups. 3Com Corp.'s TippingPoint unit began a similar program, called the Zero Day Initiative, in 2005, through which it buys vulnerabilities and exploits.
Pay-for-flaw market
Is paying for vulnerability info the right approach?

Vulnerable Commodity: Security experts debate the merits of buying info from the digital underground

Late last month researchers at security vendor Determina identified a flaw in Vista, but it was only exploitable by a local user. Microsoft acknowledged the vulnerability, which also affects older versions of Windows.

The latest iDefense challenge asks researchers to submit a new, unpublished, remotely exploitable vulnerability in either Vista or Internet Explorer 7.0 before the end of March. The flaw must enable an attacker to execute arbitrary code on one of the applications. The company will pay $8,000 for such a flaw, and said it will buy up to six flaws total. Anyone who submits working exploit code for a flaw in IE 7 or Vista can earn a bounty of $2,000 to $4,000, as well.

As justification for the Vista challenge, iDefense cited the dominance of Windows and IE, and said "that the decision to update to the current release of Internet Explorer 7.0 and/or Windows Vista is fraught with uncertainty. Primary in the minds of IT security professionals is the question of vulnerabilities that may be present in these two groundbreaking products." The company said the bounty challenge will help allay those fears.

The phenomenon of research organizations paying for vulnerability data has not been without its critics, but in many cases users say that as long as the organizations like iDefense and TippingPoint follow responsible disclosure practices , how the data on a new flaw gets to the affected vendor is of little importance. Someone is going to find the flaw eventually, so it's irrelevant whether the researcher was paid for it, this argument goes.

But software vendors have been critical of the pay-for-flaw market, saying that it encourages irresponsibility. The programs have flourished, despite some initial skepticism among researchers. By the end of its first year last summer, TippingPoint's ZDI had 400 registered researchers and had disclosed 30 flaws. Under the ZDI program, TippingPoint pays researchers on a sliding scale for finding new vulnerabilities in commercial software packages. The amount paid depends on a number of factors, including the severity of the flaw and whether the software it's in is widely deployed. TippingPoint then acts as a clearinghouse and submits the vulnerability data to the affected vendor and handles the rest of the disclosure process.

"The researchers don't have to deal with any of the frustration of dealing with the vendors," Dave Endler, director of security research at TippingPoint, said in an interview last year.

Tags: Information Security Laws, Investigations and EthicsEmerging Information Security ThreatsSecurity Industry Market Trends, Predictions and ForecastsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Information Security Laws, Investigations and Ethics
Melissa Hathaway urges more cooperation, government attention to cybersecurity
Cybersecurity czar candidate questions clout of new position
DHS fills National Cybersecurity Center post
FTC shutters rogue ISP for hosting malicious content, botnets
Experts optimistic of Obama cybersecurity plan
WH cybersecurity plan needs private sector guidance
Obama announces creation of cybersecurity coordinator position
Cybersecurity Act of 2009: Power grab, or necessary step?
Face-off: Who should be in charge of cybersecurity?
Feds should get private sector advice on cybersecurity

Emerging Information Security Threats
Cybercriminals invest in social networking attacks
Best practices for (small) botnets
Cybersecurity grant to fund research into critical infrastructure threats
RSA security conference 2010: news, interviews and updates
Hackers to sharpen malware, malicious software in 2010
Modern malware, stealthy botnets, adapt quickly, expert says
New ransomware Trojan pushes victims to buy software
Bruce Schneier on outsourcing, awareness training
Marcus Ranum on cyberwarfare, infosec careers
US-CERT warns of BlackBerry snooping software

Security Industry Market Trends, Predictions and Forecasts
Using unique device identification for bank website security
Cybercriminals invest in social networking attacks
Entering 2010: The economy and the state of information security
RSA's Coviello declines cybersecurity coordinator post
Schneier-Ranum face-off, part1: The future of information security
Cybersecurity grant to fund research into critical infrastructure threats
Hackers to sharpen malware, malicious software in 2010
Part 1: Marcus Ranum on the state of information security
Part 2: Marcus Ranum on the state of information security
Part 4: Marcus Ranum on the state of information security
Security Industry Market Trends, Predictions and Forecasts Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CALEA  (SearchSecurity.com)
cyberstalking  (SearchSecurity.com)
FERPA  (SearchSecurity.com)
HSPD-7  (SearchSecurity.com)
I-SPY Act  (SearchSecurity.com)
Information Awareness Office  (SearchSecurity.com)
intelligence community  (SearchSecurity.com)
lawful interception  (SearchSecurity.com)
lifestyle polygraph  (SearchSecurity.com)
vulnerability disclosure  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts