Slashdot Mirror


Vista Zero-Day Exploit For Sale

Snakepit Bit writes "Underground hackers are hawking a zero-day exploit for Windows Vista at $50,000 a pop, according to computer security researchers at Trend Micro. The Windows Vista exploit, which has not been independently verified, was just one of many zero-days available for sale at an auction-style marketplace infiltrated by the anti-virus vendor. Prices for exploits for unpatched code execution flaws are in the $20,000 to $30,000 range. Bots and Trojan downloaders that typically hijack Windows machines for use in botnets were being sold for about $5,000." From the article: "According to [Trend Micro CTO Raimund] Genes, the typical price of a destructive exploit has increased dramatically, driving an underground market that could exceed the value of the legitimate security software business. 'I think the malware industry is making more money than the anti-malware industry,' Genes said."

23 of 233 comments (clear)

  1. Ah... by JoshJ · · Score: 5, Funny

    'I think the malware industry is making more money than the anti-malware industry,' Genes said.
    Thank you, Captain Obvious.
    *salute*

    1. Re:Ah... by Swimport · · Score: 3, Insightful

      I dont think its that obvious. There are a lot of people out there that pay for security software. Not to mention the large corporations that spend millions on it. Not even mentioning the tech support jobs created to combat spam and hackers.

    2. Re:Ah... by Swimport · · Score: 5, Insightful

      Even assuming the cost of damages from malware exceeds the money spent on anti-malware doesnt mean the damages are ending up in someones pocket. If a company is crippled for days it may cost them millions but the person responsible for the damages doesnt necessarily get anything. Just as with spam. If you send out 100 million spam emails and make $10,000 the loss in productivity likely exceeds $10,000.

    3. Re:Ah... by Anonymous Coward · · Score: 3, Funny

      The malware industry doesn't exactly report their numbers,

      http://www.microsoft.com/msft/earnings/

      keep offices,

      Their headquarters is here

      or publish a trade rag.

      http://www.microsoft.com/technet/technetmag/

  2. Auctions by bucketoftruth · · Score: 4, Interesting

    Where are these online auctions for this information? Or does that information come with the same spam I get hawking "3 million email addresses for $1000!" I'd love to know what software they use to host such a site. I expect it's probably more secure than the pentagon's systems.

    1. Re:Auctions by ZPWeeks · · Score: 5, Funny

      No, it IS the Pentagon's system!

  3. closed systems by drDugan · · Score: 3, Interesting

    this seems a natural result of closed-source software companies

    I think it is a good thing: it goes to show that having closed systems puts information access at a premium instead of service and real, tangible results for your customers. Open source systems don't have this problem (they have others, 'bot' not this one).

    1. Re:closed systems by badriram · · Score: 5, Insightful

      please, this has nothing to do with closed systems and open systems. This has more to do with people wanting compromised machines to do their bidding, be it spam, ddos attacks, get personal info etc. These people obviously make a lot of money, so obviously they are willing to pony up thousands of dollars for a flaw that might give them access to hack millions of computers. If Linux/bsd/osx were at 90% market share, I am sure these &#@%$! will still be selling/buying vulnerabilities at these prices. (unless ofcourse it is harder to hack them, then prices would higher)

    2. Re:closed systems by indigoid · · Score: 4, Insightful

      No, you're wrong, actually. They are much better off pwning eleventy billion little computers, because they are way harder (or impossible?) to effectively blacklist, filter and otherwise protect from.

      A big server with lots of bandwidth will stand out like a honeymooner's dick (thanks Billy Birmingham) and be rapidly blacklisted. See: RBL, ORBS, etc

      --
      P-plate adventurer
    3. Re:closed systems by badriram · · Score: 3, Insightful

      Ill bite.

      1. Linux servers do not have a higher marketshare than windows servers, check your facts.
      2. Servers be linux or windows, typically have people that are more computer literate, hence are alrady better protected, monitored, and locked away.
      3. millions of unmonitored desktops, with careless users, with broadband connections will always be a better target.

  4. l33t hax0r by pchan- · · Score: 5, Funny

    the typical price of a destructive exploit has increased dramatically, driving an underground market that could exceed the value of the legitimate security software business. 'I think the malware industry is making more money than the anti-malware industry,' Genes said."

    Sounds like I need to switch jobs. Finally, a job where discovering Windows bugs will pay off instead of just generating more work for me.

    1. Re:l33t hax0r by AltGrendel · · Score: 4, Interesting

      Finding the bug is one thing. Being able to write a program that will successfully exploit it on a consistent basis is another.

      --
      The simple truth is that interstellar distances will not fit into the human imagination

      - Douglas Adams

  5. What do Linux virii cost? by k1e0x · · Score: 3, Funny

    Or are they open source..? ;)

    --
    Bringing liberty to the masses. - http://freetalklive.com/
  6. Re:Please define "zero-day" by Omnifarious · · Score: 3, Informative

    No, it's an exploit released before there's a patch that fixes the hole the exploit exploits.

    zero-day warez are cracked (i.e. DRM removed) versions of programs available on the same day or before the commercial versions are released.

  7. Economy by rowama · · Score: 3, Funny

    This is just another example of how M$ is good for the economy. All you anti-capitalist, libertarian nerds can sit down and shup up, now.

    Kidding, of course.

    1. Re:Economy by EnsilZah · · Score: 5, Insightful

      I was under the impression that libertarians were the embodiment of capitalism.

  8. Oh come on now... by jorghis · · Score: 5, Insightful

    You know the people selling this stuff arent exactly the most ethical folks in the world. Do you think that just maybe they are asking for 30k without any really good exploits to give you for that money?

    It isnt smart to assume that there are zero day exploits for Vista available just because some reporter says he heard there is someone who wants to anonymously sell you an exploit he promises is really good. Even if these exploits are real (big if) noone said anything about how big of a security hole we are talking about here.

    How about if I tell you that I heard someone offered to sell an Linux exploit of an unknown nature for 50 grand? Should we all run around talking about how Linux is insecure now?

    This seems like a journalist trying to come up with something good to write about and slashdot forwarding it on as anti-ms fud.

    1. Re:Oh come on now... by CODiNE · · Score: 4, Insightful

      People who pay $50,000 for something aren't afraid to kill you if you lie to them. This especially makes sense if the mafia / SPAM connections are true.

      --
      Cwm, fjord-bank glyphs vext quiz
  9. Re:Why doesn't Microsoft buy those out? by mochan_s · · Score: 3, Insightful
    I really don't get it. To me it seems it would be economically wise to buy these out and then fix the bugs.

    Why do?

    After a user buys a copy of Vista, Microsoft receives no more money from the user.

    It would probably be economically wise to spend time in developing another product.

  10. Yeah, right by LaughingCoder · · Score: 5, Interesting
    ... according to computer security researchers at Trend Micro ...
    ... like Trend Micro doesn't have anything to gain by people thinking there are Vista exploits. Seriously, Norton, McAfee and Trend Micro are all worried that their golden goose may be cooked if Vista is significantly more secure than XP. And I loved the use of the cloak-and-dagger word "infiltrated" to strike further fear into people. This seems to me little more than a sad attempt to remain relevant by an anti-virus vendor.
    --
    The more you regulate a company, the worse its products become.
  11. Hi, welcome to... by thrill12 · · Score: 3, Funny

    0-day-bay, your place for new gadgetries in the world of ScRiPtKidDieS GoNE CoMmErCIal !
    Today, we have on offer a few jolly nice samples of the finest goods, what do you think of:
    * Evil worm 2 - Dr.Evil himself would promote this one, if he were a real person, but alas: this Evil worm 2 does not come with frickin' lasers on its head. Made in China, this worm can eat away the fumbly firewalls of most present day Windows machines !
    All that, at a price of just $30.000 !

    * Glasnost x-ploit - Oh my, in the Western world we make the x-ploit, but in Russia - where this lovely piece of software was born - they x-ploit you ! Just like in the old days of Gorbatchov, this Glasnost worm certainly opens ... backdoors ! ha ha !
    For just the measle amount of $15.000, you could have your very own Glasnost'ed Windows botnet in no time !

    Last but not least, we wouldn't want to forget our bestseller, our hitman, our top product in the fine world of Windows Redecorating Software : Yoghurt Trojan !
    Not the milk-product, but you could say it's milky white cream covers most Windows PC's pretty well ! It has no aftertaste like some worms, and definitely likes to morph into different appearances ! It can definitely lighten the spirits of whoever is at the controls and includes a lovely "MAD"-button in case some law enforcement officer decides to peak into your operation : no more evidence, because no more Trojaned PC's survive the Mutually Assured Deletion of this king of kings !
    All that, for just $50.000, it's a bargain !

    --
    Slashdot: stuff for news, nerds that matter, matter for news, stuff that nerd
  12. Re:Please define "zero-day" by Anonymous Coward · · Score: 5, Informative

    The media idiots and security vendors bastardized this term. 0-day originally meant an vulnerability unknown to the vendor hence there is no patch or work-around for it.

    Then security vendors tried to use it to mean any vulnerability without a patch, known or unknown because then they could rightly claim that their software mitigated a 0-day vulnerability, which really meant thier software could mitigate a known vulnerability. That's where the media idiots jumped in because 0-day sound cool and scary.

    There is no point in trying to correct them. That ship has sailed. Just like "hacker" now means criminal when the original definition was a badge of honor.

    Now that the vulnerability is known, it is just an unpatched vulnerability.

  13. Where's the Popularity Argument Now? by twitter · · Score: 3, Insightful

    Oh, ho ho. All the apologists are quick to argue that, "The only reason the bad guys target Windoze is because it's popular." What bullshit that is.

    Vista has what market share now? Less than Mac or Linux I'm sure and everyone knows that it's going to stay that way for years. Yet there's already a market for exploits. What this should tell you is that the value of an exploit it's ability to work, regardless of market share. The bad guys know that M$ security sucks and that the holes they buy today will be good for months if not years to come. No one bothers with GNU/Linux exploits because the GNU/Linux market is fragmented and quick healing. Linux exploits don't take down every distribution but just about every distribution is quick to fix problems. GNU/Linux exploits, relative to Windoze, don't work or last long.

    --

    Friends don't help friends install M$ junk.