Showing posts with label Zerodium. Show all posts
Showing posts with label Zerodium. Show all posts

Wednesday, 4 November 2015

Hackers Would Have Earned $ 1 Million With iOS9 Leak


A contest where hackers could earn $ 1 million with a zero-day vulnerability in iOS9 allow an attacker to get permanent access to the unit has produced a winner. That Zerodium let through Twitter know, the company that organized the contest. Critics are skeptical.

Participants in the competition were until 1 November to submit their zero-day exploits. In order for the amount of money needed to qualify the vulnerability could be attacked without user interaction, except for visiting a malicious web page. Also attacks came via SMS or MMS to reward eligible. Now Zerodium argues that the contest has produced a winning team.

Critics are skeptical and say that without evidence ultimately a PR stunt is. Across Vice Magazine late founder Chaouki Bekrar know that performing a jailbreak remotely allowing permanent access to the device can be obtained at least two or three additional exploits required. Several teams went to this was fixed and Bekrar plan to extend the deadline until another team came a few hours before the expiry of a solution.

To which team it exactly goes and what kind of vulnerabilities not know there used to attack Bekrar late. He also will not say how much he will sell the exploit. Zerodium buys vulnerabilities from researchers to then resell these to government organizations.

Wednesday, 23 September 2015

Business Lauds $ 1 Million For Zero-Day Vulnerability In iOS 9



A company that zero-day vulnerabilities from researchers buys and prepares them to government agencies and large enterprises to sell through has a reward of one million dollars promised for a zero-day vulnerability in iOS 9. This is a vulnerability that needs to be through the browser are attacked and the attacker gives permanent access to the iOS device.

There should be no further user interaction is required, except to visit the web page. In addition, researchers get paid even if the attack can be performed via SMS or MMS. Zerodium, as the company is called, says that the vulnerability should be exclusive. In its own text with the requirement for zero-day talk of an "untethered jailbreak", but according to security expert Robert Graham, this is a red herring because it Zerodium not a jailbreak to do.

"A 'browser-based jailbreak is the same as a browser-based zero day", says Graham. According to the expert, there is intelligence from a high demand for these types of vulnerabilities. Especially now, half of iPhone users now iOS 9 installed would intelligence lose access can get into the systems of targets. Unless they have a new zero-day attack, says Graham. Since Zerodium states that the zero-day vulnerability to be exclusive, he expects the company's vulnerability will then sell them to multiple parties.