Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

in all seriousness, where is the marketplace for zero-day attacks? and how does one bring goods to market there?


Find vulnerability, develop exploit, sell to http://www.zerodayinitiative.com/ or http://labs.idefense.com/vcp/ if you are a "White Hat" or the Russian mafia if you want to make more money and don't care what your exploit is used for.

Once upon a time http://www.wslabi.com/ tried to create some kind of eBay for vulnerabilities too but it did not seem to go well.


How would one get into finding vulnerabilities with no prior security knowledge? I've always been interested in white hat security


without a doubt, the best book on the topic is:

http://www.amazon.com/Art-Software-Security-Assessment-Vulne...

Mark is one of the best vulnerability researchers in the world. We used to hang in the same groups, and I remember that there was a 2-3 month period where he found and wrote exploits for vulnerabilities in almost a dozen different operating systems on 5-6 different architectures. the guy is a god

Back then the only way to learn was to try it out yourself. there were no books, only phrack, IRC, and setting up boxes on your own network and having a go at them with a debugger running. you really have to be motivated, as the work is laborious, but worthwhile because there is nothing better than the rush you get from developing your own exploit. it is awesome that ppl like Mark are now writing books and dumping the knowledge they have gained through decades of real experience

there are different types and categories of exploit. local apps and targeting privilege escalation, kernel exploits, server daemons (ie. anything that has a port opening and waiting for a connection), crypto implementation exploits and then webapps and browsers (more popular today).

then there are different discovery methods: black box testing, where you throw data at an unknown system and through known inputs and outputs figure out what is in the box. white box testing, where it is still closed source, but you are able to attach a debugger, and then code auditing - which is simply going through the source code and attempting to find common errors that you can exploit.

you will find that you will levitate to one particular type as you learn. for eg. for me personally it was IIS server (found and developed 6 diff vulnerabilities for IIS 4.0 and 5.0), NT kernel and web apps. good luck with it - if you find something, send it to me :)



http://myne-us.blogspot.com/2010/08/from-0x90-to-0x4c454554-...

This is a guide I found on /r/reverseengineering on reddit (which actually has a decent community, considering the fact that its on reddit)


There are dozens of forums hosted on Katz Global anonymous servers. Payment happens via anonymous gold-based payment systems like Pecunix. A top-of-the-range zero day exploit can set you back at least 5 figures. Also available: botnets for hire, stolen credit cards, WoW accounts, fake 'high yeild investment' scams and anything else you could think of.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: