Sidenote: I think I have a guess based on a prior conversation, but for the edification of HNers: $3,000 is how many orders of magnitude below the market worth of that vulnerability?
I can't tell you exactly how much though because I'm busy tracking down his email address so we can be his 8th grade internship.
I remember when I was a teenager making more than my parents (dot-com boom) and money I was making was just piling up. I had virtually no goals that would require money back then... of course now as I get older, it's exactly the opposite, plenty of goals, no money :)
The bug is in Binary Search - one of the most fundamental algorithms in programming. It's been around in a published implementation of Binary Search since 1986, and the implementation of Binary Search for the JDK was broken for 9 years. This bug was only discovered in 2006, when someone's program broke.
If you haven't heard of it, read more here: http://googleresearch.blogspot.com/2006/06/extra-extra-read-...
Quick Summary - to get the "middle" element of the array, the line is this: int mid = (low + high) / 2;. This overflows when low + high is larger than MAX_INT, causing havoc.
Some people learned to whistle the tone, while others used bird calls, and even a whistle given free by Captain Crunch (the cereal).
I heard this around the age of 14 though- so it's possible my memory is foggy.