I assume this is why Stuxnet had so many zero-day exploits in it. The agencies behind it had security firms feeding them.
I assume this is why Stuxnet had so many zero-day exploits in it. The agencies behind it had security firms feeding them.
I have no firsthand knowledge of how these connections work (the gossip I hear tends to involve firms proffering vulnerabilities to middleman "commercial" firms --- not ZDI, by the way --- but who knows?). But I'm skeptical of the idea that security research firms are a real feeder for vulnerability intel to NSA, because based on the people NSA spits back out into commercial industry, they appear to have a very, very capable internal research staff.
The market for 0days has been cooling off in recent years, but for a good decade there you could sell 0days, even mediocre ones for six digits. Nowdays you'll need a pretty good vuln for six digits, and something pretty stellar for seven (this isn't unheard of). ZDI, frsirt and others got into the game as middlemen. They allow(ed) you to not know who the final purchaser is and would allow you to sell 0days that may or may not be interesting to a government entity - in this case ZDI, etc would swallow the cost.
Sorry for the questions, no contact info in your profile. Answers from anyone would also be appreciated.
Have you personally ever sold a vulnerability?
(And obviously, I don't have such a 0day to sell, so I can't prove that they would actually pay up.)
Disappointed that 'mediocre' vulns got interpreted in this thread as 'trivial'.
Mediocre doesn't mean trivial, extremely scoped or useless. Mediocre means that it is for sensitive but not widely deployed software, for widely deployed software on default config but is post-auth or is not reliable, or it is reliable and yiels high auth but requires pairing with another vulns (i.e. memory disclosure) or extended recon (revision number, etc).
A MySQL bug affecting recent revisions that causes arbitrary file overwrites with semi-controlled content but that requires unprivileged (guest) auth would meet this criteria.
Apologies for the confusion with the word 'mediocre' - I figured people here would know.
In general organizations in the offensive world will pay more than those in the defensive world. This is not a hard and fast rule, but mostly it is the case that offensive network operations stand to gain more from the use of 0days than vendors stand to lose by not paying for the disclosure to patch them. It's not really a good calculus to use data from vendors sales to calculate the other.
Not speculating about nation states here but 'groups': making good money from post-Auth MySql RCE not totally absurd - Amazon, Rackspace, HP, Heroku and Jelastic all offer MySql-as-a-service, where you are given low privilege (maintained, geo-redundant, etc) account access to shared MySql instance. If there's more than five digits of business value stored in that database then a five digit exploit makes sense.
Or think about any of the (poorly written) bitcoin services out there that use some default phpAdmin creds for a database that also hosts their vault.
As for the "market assessment" I find it implausible. It seems to be based on the assumption that the demand for capabilities has decreased over time while the availability of good bugs has increased. This is at odds with reality.