Exploring Previously Unknown Remote Kernel Bugs Affecting Android Phones
pleasestopnamingvulnerabilities.com
pleasestopnamingvulnerabilities.com
This isn't really the main focus of the article, but I find this really interesting. There are teams of full-time Chinese researchers looking for and reporting vulnerabilities in Android? Are they doing this to win the bug bounties? If so, it sounds like Google's bug bounty program is really paying off.
My guess is they're either working for the bug bounties, or they're employed by a company that uses Android extensively and wants to make sure its secure.
Being China, its also possible that the Chinese government indirectly or directly sponsors this research, since Android is by far the most common smartphone OS there.
edit: C0RE Team [1], who also has many contributions seems to be an independent research company, who may be doing it just for the bounties.
[0] https://source.android.com/security/overview/acknowledgement...
If there's a discrepancy, then that's possible evidence one group might be hoarding bugs, or at least waiting for notification approval from, e.g., a domestic intelligence agency.
sometimes infosec seems the most dreadful field.
https://www.reuters.com/article/us-bitfinex-hacked-hongkong/...
If you're a world class exploit developer working full time, expect earn a few hundred million $ per year.
Of course there exists a whole industry full of people that'll offer you silly 6 digit salaries.
https://www.fbi.gov/wanted/cyber/evgeniy-mikhailovich-bogach...
This guy is a good example of someone with a decent career in infosec operating on the right side of the law (Within his own jurisdiction, anyway).
If you want to do charity reporting bugs, then you obviously will get paid like charity workers do.
Wire fraud in the high tens of millions is a daily thing. Shit out a OWA RCE bug and you can make billions swapping out bank account info in emails.
All the money in the world is controlled by insecure computers, of course skilled exploit devs can drown themselves in it.
Generally, single digit millions/year seems a reasonable expectation for a very talented (and ethically flexible) exploit practitioner. Beyond that requires luck and right place / right time.
It doesn’t even have to be a company with any infosec staff, think any big factory or a mine. Large wire transfers over email are a daily thing.
I truly believe that the amount of people that could earn hundreds of millions a year doing this full time isn’t even that small.
The most famous one I'm aware of got $100M over two years and didn't get to keep it. http://fortune.com/2017/04/27/facebook-google-rimasauskas/
But the amounts of money you could steal with relatively little work are truly immense.
>The most famous one I'm aware of got $100M over two years and didn't get to keep it. >http://fortune.com/2017/04/27/facebook-google-rimasauskas/
This guy seems to be the polar opposite of a world class exploit dev, but he got pretty far.
However he was also a pretty small player, I’m on my phone now but I’ll try to post some useful links in the morning.
Stealing $100M over two years from FB and Google? Sounds world class to me. Social engineering isn't an inferior skill to actual code exploits.
Yeah, I think at this point the largest actors in this field have stolen $1B+ just by themselves.
>Social engineering isn't an inferior skill to actual code exploits.
For this specific purpose it probably is. With a single webmail exploit you could trivially be stealing similar amounts in days from vast numbers of businesses. All you need to do is automatically (or manually) replace bank account information in the emails. This is a relatively simple task to automate.
A $20M wire being sent to some random bank account copypasted from OWA is nothing out of the ordinary. There are thousands, probably tens of thousands potential targets.
At least the FBI seems to think that these email compromises are a 5 billion dollar industry, https://securityledger.com/2017/05/fbi-business-email-compro... We haven't even seen any fancy 0days being used yet, the whole industry is prime for disruption by more sophisticated, more efficient actors.
In the face of all this it really seems hard to argue that a world class exploit dev couldn't be earning hundreds of millions a year with relative ease.
https://www.bloomberg.com/gadfly/articles/2017-02-06/google-...
This has created a strange ecosystem for app stores in China, which depend on vulnerability exploitation in varying degrees for installation privileges.
Maybe some of the work is dual use, but the primary motivation for funding this kind of vuln discovery and exploit development seems to have been App Store ecosystem development in China.
Can you explain that a bit more? 3rd party app stores are legitimate on Android, so why would they depend on vulnerability exploitation?
I hope you are being sarcastic; guess again!
It draws public attention to an issue better than any CVE-2017-XXXXX would do.
No, keep it up. Dictionary words are far easier to remember than specific numbers.
I can't speak for what the value-add is there, but I don't see any harm from it.
I expect to see drastically more work into IoT devices once tooling and knowledge sharing gets better. A lot of the articles right now begin and end with binwalk. Great tool but that's just the start.
The only hard part of embedded work is that it's really, really difficult to collaborate with anyone as VR is always filled with incredible drama and the talent pool of individuals willing to work on this (for free) with the prerequisite knowledge is almost non-existent.
Good luck. And thanks for not coming out with another media campaign first and interesting research second.
The exploits i'd bet are still in the human written weird stuff and not unfolded loops and boring setters/getters.