Pardon my ignorance, but how would this work?
What Happens When You Send a Zero-Day to a Bank?
221–230 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#222Earlier quoted context omitted.
The bank may be able to demonstrate that the vulnerability was not exploited by, e.g., showing that the order preview page was first loaded with the same parameters, or showing a same domain referer.
The article covers this: >Also their engineers made it clear that unauthorized transactions like this and later shown below would not be distinguishable from other legitemate transactions.
If you kept buying and selling on that account, including with the supposedly-hacked-purchased shares, you'd need to explain why you didn't bring it up until now.
Re: What Happens When You Send a Zero-Day to a Bank?
#223Re: What Happens When You Send a Zero-Day to a Bank?
#224There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
This was introduced 3 days ago https://twitter.com/martenmickos/status/854321634404061185
HackerOne will work with friendly hackers on a best effort basis to verify the legitimacy of a vulnerability, reach out to and verify the identity of an individual at the affected organization, then share the vulnerability with the organization so it can be resolved.
Seems like it address most of the problems of educating the organization so they don't threaten you.
Re: What Happens When You Send a Zero-Day to a Bank?
#225Earlier quoted context omitted.
Personally I think this is a function the the FBI should fill. However, there is a risk they would sit on zero days and weaponize them (or give them to another three letter agency). I wonder if an org like the EFF could add this to their scope.
> However, there is a risk they would sit on zero days Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda. There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.
The EFF seems like a good choice. In general you would need to pick an organization that does not have a vested interest in using exploits.
Re: What Happens When You Send a Zero-Day to a Bank?
#226>if somebody sent you an email with that code (even if you never open the email) then you would be the unwitting owner of one share of Krispy Kreme Donuts Pardon my ignorance, but how would this work?
"But this only affects people that are logged in, right? Yes ..."
So I suppose what happens is, that the user is already logged into the service and thus has a cookie for the service in his browser.
If the user then somehow executes a request to the URL in the article with the same browser (eg viewing a malicous email with the IMG tag in a webmail client), the browser will enclose the cookie in the header of the request. This makes the request automatically authenticated.
Re: What Happens When You Send a Zero-Day to a Bank?
#227Surely one acquisition and 9 years later this isn't still an open vulnerability… right? It'd be nice if the author discussed that.
Re: What Happens When You Send a Zero-Day to a Bank?
#228There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
It sounds like you need HackerOne Disclosure Assistance https://support.hackerone.com/hc/en-us/articles/115001936043... This was introduced 3 days ago https://twitter.com/martenmickos/status/854321634404061185 HackerOne will work with friendly hackers on a best effort basis to verify the legitimacy of a vulnerability, reach out to and verify the identity of an individual at the affected organization, then share the v…
Re: What Happens When You Send a Zero-Day to a Bank?
#229Earlier quoted context omitted.
Or you can just post your findings to full disclosure and call it a day.
What incentive, besides good-boy points and experience/publicity/etc (for more funding), do researchers have to do this?
The more unpatched vulnerabilities there are in existence, the more lucrative it is to be involved in any part of the computing crimes community.
It's like reglazing a broken window in your neighbor's garage at your own expense, because you don't want burglars to see it and start casing other properties in the same neighborhood based on the conditional probability that a visible broken window indicates a higher incidence of other exploitable vulnerabilities.
It's also important to pursue the very easily exploited vulnerabilities, because when you get rid of all the low-hanging fruit, the people who can't already climb the tree won't survive long enough to learn how. You're cutting a lot of bootstraps so that immature criminals can't pull themselves up by them.
Re: What Happens When You Send a Zero-Day to a Bank?
#230There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…