Microsoft pays $100K bounty to hacker
business.financialpost.com
business.financialpost.com
I found a cross site scripting vulnerability in Bing.com that was kind of hilarious. Searching for:
</script><script>arbitrary js</script>
in the main search box would execute the code on the results page. I mean, holy shit. I could not believe it. I emailed their whitehat service and they fixed it but I never received a bounty.> That vulnerability in Internet Explorer was known as a “zero-day” because Microsoft, the targeted software maker, had zero days notice to fix the hole when the initial attacks exploiting the bug were discovered.
> The vulnerability underlying CVE-2013-3897 was found internally at Microsoft and would have been fixed in MS13-080. However, in the last two weeks, attacks against the same vulnerability became public, but since the fix was in the code already, it enabled Microsoft to address the vulnerability, CVE-2013-3897, in record time.
https://community.qualys.com/blogs/laws-of-vulnerabilities/2... (unnecessary text omitted)
in warez it was a folder on the ftp server that would list all the latest releases from that day, to save you from navigating all the /pub/whatever folders over your slow 14.4k connection and so that the distributors would only have to grab from one place.
and somehow in this history the pronunciation changed from "oh day" to "zero day" and was re-appropriated as an infosec term.
edit: just read the definition in OP, it is hilarious.
I think, for such a huge payout, and for what they said they would pay this amount for is a _new_ tactic to defeat Microsoft's DEP[0] ASLR[1] and ROP[2]. All of these defence mechanisms have been broken before, but as I mentioned Mr. Forshaw has probably developed a novel new technique to defeat these checks.
Lastly, and probably least likely, I know academia and MS Research have been working on ways to sandbox applications. It's possible he has developed a way to break out of the sandboxes.
All of this is speculation, I hope soon we will have access to what he was able to accomplish.
[0] http://en.wikipedia.org/wiki/W%5EX [1] http://en.wikipedia.org/wiki/ASLR [2] http://krebsonsecurity.com/tag/enhanced-mitigation-experienc...
- the OP
new mitigation bypass technique
- http://www.contextis.co.uk/news/congratulations-james-forsha...
- http://blogs.technet.com/b/bluehat/archive/2013/10/08/congra...
That's no longer true, right?
I'm honestly quite amazed. When Chrome first came out, I remember asking my teammates why we were wasting money on developing a browser, thinking it would never be more than a niche product. Another reason why I'm not Google's CEO, apparently.
>From the statistics below (collected from W3Schools' log-files over a period of ten years), you can read the long term trends of browser usage.
These are the browsers that hit W3Schools, a site for people that need quick reference when making webpages, not across the internet.
Javascript performance was pretty dismal until Chrome came around, and then everyone had to up their game. Until Android, mobile platforms were tightly controlled walled gardens (although Windows Mobile was amongst the least worse). Now everyone wants Google Mail, Maps and Search on their mobile devices.
Google ultimately makes money through usage and the platform + apps/browser don't matter that much financially. Without Chrome and Android, there is a strong possibility of being cut out completely.
Yes it does matter, at least some. No one even knows what the bar is if no one is using it.
Someone could put together a wickedly fast browser with fantastic privacy controls, release it tomorrow, but if no one used it, it wouldn't have any effect on major browser makers.
JS performance went up in other browsers due to Chrome only because Chrome was gaining users (even if the base was small at first), mostly because they were able to push Chrome from Google.com itself.
As a web developer I hope the trend does not continue.
While MSIE may be 'good' browser (tastes may vary, I find the UI horrible) it's damaging to the web ecosystem to have MSIE leading the marketshare. It's advantageous for Microsoft to limit new features and keep interoperability between browsers low. As a result the entire web using public loses out on having new features and having a broader choice.
Chrome and Firefox are built on open source software, so when an issue occurs you can participate in the process of it being fixed.
Chrome and Firefox are awesome though.
Netmarketshare attempts to measure the latter and shows IE on top.
http://www.netmarketshare.com/browser-market-share.aspx?qpri...
So it depends on what your definition of "popular browser" is. Is it the browser that's used by most people? That would be IE. Is it the browser that most browsing happens? That would be Chrome. Of course, this is ignoring the fact that both Statcounter and Netmarketshare are not perfect and don't cover all or even most sites' logs.
As others have noted, W3schools only measures hits to the W3Schools site, which is not even close to be being representative of the web.
BTW, I personally think the browsing-time metric is better than unique-users, because applying the latter metric to music would have had Rebecca Black as the most popular artist of 2011. Which conclusion, though true under some definitions, might not be quite as useful as other possible conclusions.
http://www.w3counter.com/trends
(The bump in the Safari line was the inclusion of Mobile Safari in the Safari share statistic)
The title of the article: "Microsoft Corp pays US$100K bounty to hacking expert who uncovered Windows bug that could have been used to launch remote attacks"
To me, this level of editorializing approaches arbitrarily close to lying.
No, they paid US$100k to a white-hat, someone who struggles against black-hat hackers. If a headline can't distinguish between white hats and black hats, educated writers normally add some words to clarify their meaning -- and they did. But the submitter omitted those words. Hence, lying.
Guy predicts the higgs boson particle.
World renowned physicist Foo Bar, accurantly models existance of boson particle.
---See the difference? The title is BS. I expected a guy from Pakistan or somewhere third world finding the bug.
Your mock headline would be more accurate if it said "physicist models higgs boson". Hacker is a perfectly valid job title for a security researcher.
PS: A security researcher from Pakistan has been bagging a lot of Bug Bounties recently. Look up news on Rafay Baloch
Microsoft pays US$100K to hacking expert to launch remote attacks