Earlier quoted context omitted.
You used to be able to jailbreak one of the first iPhones and install Cydia just by visiting some page in Safari and clicking on a button, IIRC. I never did this myself, so my memories might be inaccurate though.
You're correct. jailbreak.me I think it was called
Million Dollar iOS9 Bug Bounty
41–50 of 80 posts
Re: Million Dollar iOS9 Bug Bounty
#42And all you have to do is sell your unicorn vulnerability to this company: ZERODIUM customers are major corporations in defense, technology, and finance, in need of advanced zero-day protection, as well as government organizations in need of specific and tailored cybersecurity capabilities The offer to buy RCE in PHPBB/vBulletin is a nice touch.
Re: Million Dollar iOS9 Bug Bounty
#43Re: Million Dollar iOS9 Bug Bounty
#44I might be missing something, but has there ever been any exploit (or string of simultaneous exploits) for iOS or android which meets all the criteria? It must be through a text message or web page, it must be remote, reliable, silent, require no interaction, must be entirely comprised of 0-day exploits throughout the whole chain, must affect multiple architectures and all supported devices, and must bypass all secur…
Yes, the stagefright vulnerability in Android ( http://arstechnica.com/security/2015/07/950-million-android-... )
Despite the media hype you can't root your phone with the stagefright bugs and so it wouldn't qualify for the bounty.
Re: Million Dollar iOS9 Bug Bounty
#45I might be missing something, but has there ever been any exploit (or string of simultaneous exploits) for iOS or android which meets all the criteria? It must be through a text message or web page, it must be remote, reliable, silent, require no interaction, must be entirely comprised of 0-day exploits throughout the whole chain, must affect multiple architectures and all supported devices, and must bypass all secur…
You used to be able to jailbreak one of the first iPhones and install Cydia just by visiting some page in Safari and clicking on a button, IIRC. I never did this myself, so my memories might be inaccurate though.
Read more: https://books.google.com/books?id=1kDcjKcz9GwC&pg=PA9&lpg=PA...
Re: Million Dollar iOS9 Bug Bounty
#46I might be missing something, but has there ever been any exploit (or string of simultaneous exploits) for iOS or android which meets all the criteria? It must be through a text message or web page, it must be remote, reliable, silent, require no interaction, must be entirely comprised of 0-day exploits throughout the whole chain, must affect multiple architectures and all supported devices, and must bypass all secur…
You used to be able to jailbreak one of the first iPhones and install Cydia just by visiting some page in Safari and clicking on a button, IIRC. I never did this myself, so my memories might be inaccurate though.
Re: Million Dollar iOS9 Bug Bounty
#47"The whole exploitation/jailbreak process should be achievable remotely, reliably, silently, and without requiring any user interaction except visiting a web page or reading a SMS/MMS (attack vectors such as physical access, bluetooth, NFC, or baseband are not eligible for the Million Dollar iOS 9 Bug Bounty. ZERODIUM may, at its sole discretion, make a distinct offer to acquire such attack vectors.)." Can someone ex…
Stagefright (Remote Android code execution) does exactly that http://arstechnica.com/security/2015/07/950-million-android-...
Re: Million Dollar iOS9 Bug Bounty
#48And all you have to do is sell your unicorn vulnerability to this company: ZERODIUM customers are major corporations in defense, technology, and finance, in need of advanced zero-day protection, as well as government organizations in need of specific and tailored cybersecurity capabilities The offer to buy RCE in PHPBB/vBulletin is a nice touch.
Re: Million Dollar iOS9 Bug Bounty
#49And all you have to do is sell your unicorn vulnerability to this company: ZERODIUM customers are major corporations in defense, technology, and finance, in need of advanced zero-day protection, as well as government organizations in need of specific and tailored cybersecurity capabilities The offer to buy RCE in PHPBB/vBulletin is a nice touch.
So, let me get this straight, this company is in the business of buying zero-day exploits and selling them to corporations and government organizations. How does this even exist? Is it legal? Can anyone buy and sell zero day exploits with total impunity?
Re: Million Dollar iOS9 Bug Bounty
#50And all you have to do is sell your unicorn vulnerability to this company: ZERODIUM customers are major corporations in defense, technology, and finance, in need of advanced zero-day protection, as well as government organizations in need of specific and tailored cybersecurity capabilities The offer to buy RCE in PHPBB/vBulletin is a nice touch.
If I had a bug that met the criteria I'd give Apple first dibs. That way the bug would get fixed, and I'd still get my $1M.