RE: 0-day exploit..do i hear $1000?

From: Scoubidou (scoubi-bugtraq@altern.org)
Date: 10/18/01


Message-Id: <5.0.2.1.2.20011018162222.00aaed90@altern.org>
Date: Thu, 18 Oct 2001 16:30:34 -0400
To: "Don Weber" <Don@AirLink.com>, <vuln-dev@securityfocus.com>, <incidents@securityfocus.com>, <pen-test@securityfocus.com>
From: Scoubidou <scoubi-bugtraq@altern.org>
Subject: RE: 0-day exploit..do i hear $1000?

At 11:28 AM 10/18/01 -0700, Don Weber wrote:

>say 25000$ in a trust fund which has a panel of lets say 20 judges from the
>security industry, then after money is confirmed deposited to fund, hacker
>tells company what the problem is, company writes/releases patch, panel of
>Judges then read the reports on do whatever testing they themselves think
>necessary, and as a result vote on how much of the 25k is awarded to the

What about freeware? GPL? and other?
How those person are suppose to give 25k to a hacker?
Just think of OpenBSD or any other free OS. If you ever
find a security problem in OpenBSD I'm sure they'll be
happy to fix it quite quick. But I don't see how they'll be
able to pay you... I don't think seling OpenBSD and
OpenSSH t-shirts give them a lot of money.

Same thing with the people who write .cgi or other web
goodies. They do that in there spare time and share it
with the comunity to save you the time they took to
build their products. Still I realy don't understand how
those person would be able to pay you money for a bug.

Another thing is: Where they are suppose to find the money
to hire 20 judges?

For what I understand your mail was aiming mostly at M$.
I'm not a M$ fan, but I don't belive it will be faire that they
have to pay if other don't just beacause they have a more
money.

Just my .02˘



Relevant Pages

  • Re: [Full-Disclosure] The Hackers Manifesto Reloaded
    ... is not an attack on your livelihood this is merely a point for your ... The attacks upon the security industry (which is required, ... it is these peoples money that pays the employees. ... any hacker who tries to attack me for trying to provide an explanation ...
    (Full-Disclosure)
  • Re: Business justification for pentesting
    ... The answer to the question of "how much money will I lose if a hacker ... Quantifying losses requires full cooperation of the financial ... department of the company and understanding of the company business ...
    (Pen-Test)
  • Re: HĂcKe®§
    ... be "hacked" if you send the hacker your password. ... How can Microsoft prevent human error? ... >conterfieting money too bussiness's lose money os all in ... >many hidden charges or the casual double charge on your ...
    (microsoft.public.security.virus)
  • Re: Breaking Bad 24may09
    ... accounts and ever get Walt's money into the mix. ... launder Walt's money, the hacker would somehow need access to it. ... It might make sense for a billion dollar laundering operation but for Walt's measly operation I would think randomly setting up PayPal accounts around the American southwest would be sufficient. ...
    (rec.arts.tv)
  • Re: Hackers
    ... I'm pretty sure that if it could be done, not only would the hacker take ... money from the players, but also from the sites and there is no way that ... Be a part of History at: ...
    (rec.gambling.poker)