• Breaking News

    Thursday, 24 October 2013

    Microsoft Pays First-Ever $100K Bounty for Windows Bug

    Microsoft on Tuesday forked out what might be the biggest payment to a bug hunter yet: US$100,000.
    The money went to James Forshaw, head of vulnerability research at Context Information Security, for coming up with a new exploitation technique that affects Windows 8.1 Preview.
    "James' Mitigation Bypass Bounty submission will help us strengthen platform-wide mitigations that serve as a part of 'the shield' that is built into the latest version of our operating system, Windows 8.1 Preview, and increases costs to attackers by making it difficult to reliably exploit individual vulnerabilities," Katie Moussouris, senior security strategist at the Microsoft Security Response Center, told the E-Commerce Times.

    The Mote In Microsoft's Eye

    Microsoft did not disclose details of the mitigation bypass technique Forshaw discovered, and won't do so until it is addressed.
    However, Moussouris did say that Microsoft engineer Thomas Garnier had found a variant of this class of attach technique.
    Forshaw's submission "was of such high quality and outlined some other variants such that we wanted to award him the full $100,000 bounty," she said.
    New attack techniques such as the one Forshaw discovered let Microsoft develop defenses against entire classes of attack and reduces the threats from individual vulnerabilities, Moussouris emphasized.

    A Cheap Price to Pay'

    While $100,000 might seem like a lot of money, "if it's something that impacts all their products and is related to security, $100,000 is a cheap price to pay," commented Jim McGregor, principal analyst at Tirias Research.
    The bounty may indeed be cheap at the price: "There are so many companies that depend on the security of Microsoft technologies," remarked Tommy Chin, technical support engineer at Core Security.
    "Imagine how many millions of dollars could have been at stake if this exploit technique was used in the wild," Chin added.

    Bucks for Bugs

    Microsoft paid out the $100,000 to Forshaw under its Migration Bypass Bounty program, which is for the identification of truly novel exploitation techniques in Windows 8.1 Preview.
    That program was announced in June with two others.
    One is the BlueHat Bonus for Defense bounty program, which will pay up to $50,000 for defensive ideas for entries that accompany a qualifying Migration Bypass submission. In other words, researchers must submit a defense with the attack it is supposed to protect against.
    The other is the Internet Explorer 11 Preview Bug Bounty, which ran June 26 through July 26 offering rewards ranging from $500 to $11,000.
    Microsoft is not alone in offering bounties to researchers for finding bugs in its software; Google, Mozilla, PayPal and Facebook are among the other companies that also do so.
    However, Microsoft's actions are in stark contrast to those of Facebook, which was heavily criticized in August for refusing to pay out a bounty of $500 to unemployed Palestinian researcher Khalil Shreateh for notifying it of a flaw he had discovered.
    The programmer community ultimately contributed a total of $11,000 to reward Shreateh through a crowdfunding effort, and Facebook eventually apologized for its actions.

    'Cool IE Design Vulnerabilities'

    Forshaw leads the Microsoft Security Response Center bounty hunters "honor roll," having garnered a total of $109,400 for his efforts.
    In addition to the mitigation bypass, he was paid $4,400 for discovering four Internet Explorer 11 Preview bugs and a $5,000 bonus for finding "cool IE design vulnerabilities."
    Forshaw, aka "tiraniddo," also discovered a vulnerability in Oracle Java Three that, when handling reflections within the java.beans.Expression class, can be exploited to compromise a user's system.

    Motivating Bug Catchers

    "This strategy of obtaining unknown exploitation techniques is working very well," Core Security's Chin told the E-Commerce Times. "It's better for Microsoft to pay third-party talent than attempt to fight against it."
    There is "phenomenal expertise out there, including among hackers," Tirias' McGregor pointed out. "There is a risk with them -- you have to know what they're doing -- but they should be tapped."
    More companies should be leveraging the software community, including open source, McGregor told the E-Commerce Times.
    "I've had vendors tell me they don't have the resources to do this," he added, "but if they put out the problem to the open source community, it would get done."


    No comments:

    Post a Comment

    Fashion

    Beauty

    Travel

    Classifieds in india | Free classifieds india | Online Classifieds india | free classifieds india | free ads india | classifieds india | ads india | jobs in india | house india | for rent india | for sale india | matrimonial ads | india events Whitedeals IT Solutions | Whitedeals | Whitedeals IT Solutions | Whitedeals | best Software companies in Tirupur | best Software companies in coimbatore | software companies in india | Billing software in Tirupur | Billing software in coimbatore | Top companies in Tirupur | Top companies in coimbatore | Whitedeals IT | Whitedeals coimbatore | Whitedeals Avinashi | Whitedeals gps tracking | bulk sms | bulk mail Whitedeals | website design | android development | telemarketing | inventory | Whitedeals software company | customized software development | android application development | billing Software | Mobile Application Services | software development Tirupur | software development coimbatore | web designing company | billing software coimbatore | software application development india | Best ERP Software Companies | seo companies in Tirupur | seo companies in coimbatore | web designing companies in coimbatore | web design companies in coimbatore | website design companies in coimbatore | web design company in coimbatore | ecommerce development company | ecommerce development companies in coimbatore | billing software companies in coimbatore | software development in coimbatore | web application | web application development | android development | android apps development | android apps development companies in Tirupur | android apps development companies in coimbatore | web development in Tirupur | web development in coimbatore | software company in Tirupur | software company in coimbatore | internet website designers Tirupur | internet website designers coimbatore | website design and development company | website development | ecommerce development | online website development | ecommerce website TM Pooja | Kalpatharu | All Pooja Material Exports | pooja | puja | pooja mandir | poojai | prarthana | pooja table | silver plate price | silver items | pooja stand | pooja decorations | pooja samagri | puja samagri | puja items | silver pooja items | pooja items | Pooja | puja | poojai | Pooja Items | Pooja Vessels | Pooja Vastram | online pooja store | online pooja materials | free door delivery | free home delivery | ganapathi homam | vastu homam | vastu pooja homam | Online Puja (Pooja) Store | Online Puja Store | Puja Articles | Buy Pooja Items Online at Low Prices in India | pooja book | Audios | videos | Online Puja Services | Pooja Online | Hindu Temple Puja | Homams | Puja Items | pooja items | pooja vessels | pooja-vastram | Online Pooja Items | Pooja Accessories | pooja samagri list | pooja items silver | indian pooja items wholesale | puja items wholesale | pooja samagri online | pooja samagri list | pooja stores in coimbatore | puja samagri list tamil | pooja samagri online bangalore | pooja samagri online Coimbatore | pooja samagri online tamilnadu | indian pooja items wholesale | pooja samagri for ganesh chaturthi | pooja items names | pooja items online bangalore | south indian pooja items online | brass pooja items online | pooja items silver Technology News Updates | tech blogs | newtech | technews | tech blog | latest it new | tech sites | science technology | tech websites | tech news sites | mobile tech news | tech magazines | tech news websites | gadget news | latest technology inventions | latest it technology | tech site | latest technology trends | technology current events | upcoming technology | latest software technologies | best tech websites | technology news today | computer technology news | articles on technology | technology news articles | latest computer technology | recent technology | latest technology in computer | news technology | com tech | internet news | technology updates | information technology news | news about technology | science and technology news | tech news today | the latest technology | latest technology updates Classifieds in india | Free classifieds india | Online Classifieds india | free classifieds india | free ads india | classifieds india | ads india | jobs in india | house india | for rent india | for sale india | matrimonial ads | india events