Live data from Hacker News

Million Dollar iOS9 Bug Bounty

zerodium.com

41–50 of 80 posts

Re: Million Dollar iOS9 Bug Bounty

#41

Earlier quoted context omitted.

You used to be able to jailbreak one of the first iPhones and install Cydia just by visiting some page in Safari and clicking on a button, IIRC. I never did this myself, so my memories might be inaccurate though.

You're correct. jailbreak.me I think it was called

And it was resurrected later on - by comex, I think.

Re: Million Dollar iOS9 Bug Bounty

#42
post #36

And all you have to do is sell your unicorn vulnerability to this company: ZERODIUM customers are major corporations in defense, technology, and finance, in need of advanced zero-day protection, as well as government organizations in need of specific and tailored cybersecurity capabilities The offer to buy RCE in PHPBB/vBulletin is a nice touch.

It's a win-win for Zerodium. They are getting free publicity for having the biggest bug bounty ever, and if somebody actually does submit a working exploit, they sell it to their clients for a hefty profit. I'm sure there are government agencies that would pay well over a million for the ability to infect any IOS device silently and easily.

Re: Million Dollar iOS9 Bug Bounty

#44

I might be missing something, but has there ever been any exploit (or string of simultaneous exploits) for iOS or android which meets all the criteria? It must be through a text message or web page, it must be remote, reliable, silent, require no interaction, must be entirely comprised of 0-day exploits throughout the whole chain, must affect multiple architectures and all supported devices, and must bypass all secur…

Yes, the stagefright vulnerability in Android ( http://arstechnica.com/security/2015/07/950-million-android-... )

The stagefright bugs gave control over the media-player daemon of Android. This daemon is not running as root, it's even jailed with SELinux, but it has some interesting permissions like microphone-access.

Despite the media hype you can't root your phone with the stagefright bugs and so it wouldn't qualify for the bounty.

Re: Million Dollar iOS9 Bug Bounty

#45

I might be missing something, but has there ever been any exploit (or string of simultaneous exploits) for iOS or android which meets all the criteria? It must be through a text message or web page, it must be remote, reliable, silent, require no interaction, must be entirely comprised of 0-day exploits throughout the whole chain, must affect multiple architectures and all supported devices, and must bypass all secur…

You used to be able to jailbreak one of the first iPhones and install Cydia just by visiting some page in Safari and clicking on a button, IIRC. I never did this myself, so my memories might be inaccurate though.

Right! One of the famous initial iPhone OS exploits involved a vulnerability in LibTiff. Decoding a crafted .tiff in Safari would grant the site's javascript root access.

Read more: https://books.google.com/books?id=1kDcjKcz9GwC&pg=PA9&lpg=PA...

Re: Million Dollar iOS9 Bug Bounty

#46

I might be missing something, but has there ever been any exploit (or string of simultaneous exploits) for iOS or android which meets all the criteria? It must be through a text message or web page, it must be remote, reliable, silent, require no interaction, must be entirely comprised of 0-day exploits throughout the whole chain, must affect multiple architectures and all supported devices, and must bypass all secur…

You used to be able to jailbreak one of the first iPhones and install Cydia just by visiting some page in Safari and clicking on a button, IIRC. I never did this myself, so my memories might be inaccurate though.

Yep, it was a pdf parsing exploit I believe.

Re: Million Dollar iOS9 Bug Bounty

#47
post #35
post #25

"The whole exploitation/jailbreak process should be achievable remotely, reliably, silently, and without requiring any user interaction except visiting a web page or reading a SMS/MMS (attack vectors such as physical access, bluetooth, NFC, or baseband are not eligible for the Million Dollar iOS 9 Bug Bounty. ZERODIUM may, at its sole discretion, make a distinct offer to acquire such attack vectors.)." Can someone ex…

Stagefright (Remote Android code execution) does exactly that http://arstechnica.com/security/2015/07/950-million-android-...

Stagefright was not a rootable exploit.

Re: Million Dollar iOS9 Bug Bounty

#48
post #36

And all you have to do is sell your unicorn vulnerability to this company: ZERODIUM customers are major corporations in defense, technology, and finance, in need of advanced zero-day protection, as well as government organizations in need of specific and tailored cybersecurity capabilities The offer to buy RCE in PHPBB/vBulletin is a nice touch.

If I had a bug that met the criteria I'd give Apple first dibs. That way the bug would get fixed, and I'd still get my $1M.

Re: Million Dollar iOS9 Bug Bounty

#49
post #37
post #36

And all you have to do is sell your unicorn vulnerability to this company: ZERODIUM customers are major corporations in defense, technology, and finance, in need of advanced zero-day protection, as well as government organizations in need of specific and tailored cybersecurity capabilities The offer to buy RCE in PHPBB/vBulletin is a nice touch.

So, let me get this straight, this company is in the business of buying zero-day exploits and selling them to corporations and government organizations. How does this even exist? Is it legal? Can anyone buy and sell zero day exploits with total impunity?

Sure. The buying and selling tools is not the issue (depending on where you live), it's using them.

Re: Million Dollar iOS9 Bug Bounty

#50
post #48
post #36

And all you have to do is sell your unicorn vulnerability to this company: ZERODIUM customers are major corporations in defense, technology, and finance, in need of advanced zero-day protection, as well as government organizations in need of specific and tailored cybersecurity capabilities The offer to buy RCE in PHPBB/vBulletin is a nice touch.

If I had a bug that met the criteria I'd give Apple first dibs. That way the bug would get fixed, and I'd still get my $1M.

Apple doesn't pay money for security bugs.
Post reply on HN