User Controls
Selling Existing Vulnerabilities
-
2022-10-08 at 9:52 PM UTCLets say hypothetically someone had a bunch of live vulnerabilities in websites that could be used to obtain different kinds of information and that this person didn't feel like putting the time into harvesting the data, could these be easily sold?
Would the US government buy these if they were within their own websites?
Obviously it would be illegal for this person to find these, but what if the person just enjoyed finding them and wanted to make a little extra money? -
2022-10-08 at 10:34 PM UTCcan you do that for minecrafrtt
-
2022-10-08 at 10:43 PM UTC
-
2022-10-09 at 1:43 AM UTC
-
2022-10-09 at 1:24 PM UTC
-
2022-10-10 at 1:48 PM UTCAre these vulnerabilities 0day? If so Zerodium will pay a premium for those.
-
2022-10-10 at 9:57 PM UTC
Originally posted by Sophie Are these vulnerabilities 0day? If so Zerodium will pay a premium for those.
Let's say hypothetically that there was an issue with NIS and someone could modify(maybe SQL, maybe not) a request that was being sent to the server and could get back somebodies password. Things like that, but with other data like SSN, DL, DOB, MMN, etc. Maybe US government sites, maybe not. -
2022-10-11 at 4:04 AM UTC
Originally posted by Misterigh Let's say hypothetically that there was an issue with NIS and someone could modify(maybe SQL, maybe not) a request that was being sent to the server and could get back somebodies password. Things like that, but with other data like SSN, DL, DOB, MMN, etc. Maybe US government sites, maybe not.
like web app vulns of a more traditional nature? Depending on the department of the government they may have a bug bounty program. The real money is in 0days though.