Slashdot Mirror


How To Go Broke Selling Zero-Day Exploits

Trailrunner7 writes "Despite all of the hand-wringing and moral posturing about the public sale of security vulnerabilities, it turns out that not many people are buying or selling vulns, and the ones who are aren't making much money at it. A new survey of security researchers who sell vulnerabilities either publicly or in private, directed sales found that the vast majority of the flaws sell for less than $5,000. Almost none of them sell for much more than $10,000. At those prices, there's little chance that this is going to turn into the chaotic Wild West marketplace that some people predicted. It's a small, mostly controlled market that isn't making anyone rich."

16 of 66 comments (clear)

  1. Not such good news, really by 5pp000 · · Score: 3, Insightful

    It means that supply is keeping up with demand.

    --
    Your god may be dead, but mine aren't!
    1. Re:Not such good news, really by insufflate10mg · · Score: 1, Insightful

      LOL@"ZOMG BUT U WONT MAKE 5K PER DAY!"

      Spend two months per 0-day and you are mediocre. Spend a month and you're pretty comfortable.

  2. Survey participation by Dan+East · · Score: 4, Insightful

    I would think that the "companies" doing lucrative business selling exploits would not be voluntarily participating in a survey of this sort.

    --
    Better known as 318230.
    1. Re:Survey participation by michaelhood · · Score: 2, Insightful

      I would think that the "companies" doing lucrative business selling exploits would not be voluntarily participating in a survey of this sort.

      This "journalist" has never heard of selection bias, obviously.

  3. "You're doing it wrong." by palegray.net · · Score: 4, Insightful

    Selling vulnerabilities == little money
    Selling fully functional botnet time == probably a lot more

    It's unfortunate, but I don't see it changing in the near future.

    1. Re:"You're doing it wrong." by RichM · · Score: 2, Insightful

      This should be marked as Insightful.

  4. Missing component: trust in the seller by Anonymous Coward · · Score: 5, Insightful

    Right now there's no way to have much confidence that you're actually getting what you're paying for. If the exploit doesn't work, what recourse do you have? This is a pretty common element in any underworld economy, but is exacerbated by the Internet's anonymity and the newness/smallness of this particular market.

    The bad news is, other underworld markets eventually overcame this problem.

  5. Developers by Threni · · Score: 3, Insightful

    Probably companies buying exploits on their own apps - cheaper and more reliable than whatever pidgin-English speaking offshore muppets currently do QA/testing for them.

  6. (shrug) My computer is disposable. by commodore64_love · · Score: 1, Insightful

    In the unlikely event I get a computer-killing virus, trojan, or exploit (hasn't happened since 1985), I figure I'll just trash the thing and buy another one for $300-400. Computers have become disposable just like other appliances.

    --
    "I disapprove of what you say, but I will defend to the death your right to say it." - historian Evelyn Beatrice Hall
    1. Re:(shrug) My computer is disposable. by SomeJoel · · Score: 5, Insightful

      In the unlikely event I get a computer-killing virus, trojan, or exploit (hasn't happened since 1985), I figure I'll just trash the thing and buy another one for $300-400. Computers have become disposable just like other appliances.

      It's not the computer that has value, it's your data.

      --
      <Complete your profile by adding a signature!>
    2. Re:(shrug) My computer is disposable. by DerekLyons · · Score: 4, Insightful

      I figure I'll just trash the thing and buy another one for $300-400. Computers have become disposable just like other appliances.

      Must be nice to have that kind of money to burn. For many of the rest of us, neither computers nor other appliances are disposable.

  7. Re:Well, duh. by Vellmont · · Score: 3, Insightful

    I might not be the best idea to stiff someone who's highly skilled at finding security vulnerabilities in software. Especially if you ARE a software company.

    --
    AccountKiller
  8. Monetization / Productization. by khasim · · Score: 4, Insightful

    Turn the idea into a product, turn the product into money.

    Sell a service providing the customer with the FINAL (or as close to the final) product as possible.

    Use your zero-day exploit to build a zombie army and sell spam services.
    Or collected credit card info.
    Or bank account info.
    Or access to corporate networks.

    The do-it-yourself customer isn't going to spend a lot of money for something that he might not be able to verify.

  9. $10,000 ain't chump change by ralphdaugherty · · Score: 4, Insightful

    $10,000 is a chunk of change in former Soviet Union. For that matter, it's a chunk of change for me too even being in the States but not as enriching as former USSR.

    In any event my understanding from info I read (mostly here on /.) is that the big money is made from herding botnets to sell time on for spam, phishing, etc. activities. The same people who put together these exploits in packages to sell are already using them to build gigantic botnets.

    I would not be surprised if they are able to tap into the botnets built with exploit packages they sell.

    FWIW, the range of IP addresses my web site has been targeted from for phpBB spamming is truly awesome, I haven't seen anything like it before in the eight years I've had the site up. Also the amount of money reported in news as stolen from bank accounts is staggering.

    I don't know what kind of happy talk article this is, but botnets are alive and well and thriving, and someone is getting rich at the expense of lots of victims who also unknowingly supply bots for the net. Whether $10,000 from an exploit package sale, or for a multi-billion spam run, or transferred out of a bank account, it adds up.

      rd

  10. Dammit mods by Anonymous Coward · · Score: 1, Insightful

    This should be marked as Insightful.

    (Currently marked as 3, Insightful)

    You took that too literally. I think that the parent was talking about grandparent, not his post, even though he said this...

  11. $5000 not much money...HERE. by Anonymous Coward · · Score: 1, Insightful

    Maybe in the US it's not much money, but in eastern Europe and most of Southeast Asia, $5000 is a shitload of money. Some places, that's more than people make in a year.

    Maybe you think it's small change, but if you're living in some parts of southeast Asia, $5000 every 3-4 months feeds, clothes and houses your entire family.