Slashdot Mirror


$16,000 Bounty for Sendmail, Apache Zero-Day Flaws

Famestay writes "Verisign's iDefense is putting up a $16,000 prize for any hacker who can find a remotely exploitable vulnerability in six critical Internet infrastructure applications. The bounty is for a zero-day code execution hole on the following Internet infrastructure technologies: Apache httpd, Berkeley Internet Name Domain (BIND) daemon, Sendmail SMTP daemon, OpenSSH sshd, Microsoft Internet Information (IIS) Server and Microsoft Exchange Server. 'Immunity founder Dave Aitel, who also purchases flaws and exploits for use in the CANVAS pen testing tool, says its doubtful iDefense will get any submissions from hackers. "It's very hard to exploit [those listed applications]," Aitel said. "IIS 6 hasn't had a public remotely exploitable bug in it. Ever." Several other hackers I spoke to had very much the same message, arguing that $16,000 can never equate to the amount of work/expertise required to find and exploit a hole in the six targeted technologies.'"

14 of 173 comments (clear)

  1. IIS and Exchange by Anonymous Coward · · Score: 1, Funny

    Easy money....easy money.

    1. Re:IIS and Exchange by ISwearNotmyPorn · · Score: 3, Funny

      If you want to talk easy money think Sendmail.

  2. hMMM by multipartmixed · · Score: 2, Funny

    Does it count if we "find" a "hole" in the current CVS snapshot?

    --

    Do daemons dream of electric sleep()?
  3. IIS 6 by Anonymous Coward · · Score: 5, Funny


    IIS 6 hasn't had a public remotely exploitable bug in it. Ever.

    How can that be? IIS is crap! Slashdot tells me so!

    1. Re:IIS 6 by eln · · Score: 5, Funny

      No one has ever found a hole in it because no one has ever managed to keep it up and running for long enough to find one without it crashing first.

  4. Look at me, I'm a hacker by Anonymous Coward · · Score: 5, Funny

    $16000 is not worth the time to make the internet safer. Now stop bothering me while I spend my time trying to figure out how to save $15 by cracking DVDs. After that, I'm off to steal some music.

  5. Not to mention ability to convert O2 to CO2... by Kadin2048 · · Score: 5, Funny

    Also, you may be able to collect multiple bounties from different organizations for the same hole.

    True ... but I bet breaking an NDA with the Russian mob could adversely affect your ability to work in the computer-security field in the future.

    --
    "Ladies and gentlemen, my killbot features Lotus Notes and a machine gun. It is the finest available."
    1. Re:Not to mention ability to convert O2 to CO2... by peragrin · · Score: 2, Funny

      >>True ... but I bet breaking an NDA with the Russian mob could adversely affect your ability to work in the computer-security field in the future.

      I didn't sign an NDA when i started working for the..... Oh high Vladmir, what are you doing he.....

      --
      i thought once I was found, but it was only a dream.
  6. Re:Exchange by DrLov3 · · Score: 1, Funny

    Pfff.... Ms. Echange ....

    No need to find a flaw, Ms exchange will crash on it's own. :P

  7. Re:No, but... by Darlantan · · Score: 5, Funny

    Also, you may be able to collect multiple bounties from different organizations for the same hole.

    Yeah, but pimpin' ain't easy.

    --
    Fill in your four or five-letter word of wisdom here _ _ _ _ _.
  8. Re:Tried Google? by Anonymous Coward · · Score: 4, Funny

    Just to narrow it down, I redid your search with quotes and found 67. But the first one's a blast. It goes to the "w4ck1ng" forum where the thread goes...

    "Hello found this exploit: http://www.derkeiler.com/Mailing-Lis...5-04/0436.h tml I have compiled it. And when i run it under linux, it gives me this error! [cut for brevity] ./iis.exe: 3: Syntax error: word unexpected (expecting ")") Anyone ?"

    ...and the response goes:

    "you can not use exe files under unix y0u have to compile it with GCC..."

    I *think* IIS is safe from *this* guy...

  9. FYI by Slashcrap · · Score: 5, Funny

    I guess some people reading this may be more used to Windows and therefore not entirely familiar with the functionality of the Unix packages that were mentioned. Allow me to summarise :

    OpenSSH - A service you can install on a Unix system to enable remote admin access for known users.

    Sendmail - A service you can install on a Unix system to enable remote admin access for complete strangers.

    Hope this helps.....

  10. Re:$16,000 by networkBoy · · Score: 2, Funny

    Well I have one exploit for each platform.
    It is remote, and it is foolproof.
    I want the money.
    -nB

    The exploit is to take the admins family hostage, demanding whatever code you want to be run in exchange for the family's safety.
    Since you are using a phone to control the admin it is a remote exploit.
    Have a nice day.

    --
    whois gawk date unzip strip find touch finger mount join nice man top fsck grep eject more yes exit umount sleep dump
  11. $16k by Anonymous Coward · · Score: 1, Funny

    money is the source of all evil code ... wait ... or is it the other way round?