Welcome Guest ( Log In | Register )



 
Reply to this topicStart new topic
> Two For The Price Of One: New Messenger Exploit And A New Way To Get It
tansqrx
post Jul 10 2007, 10:24 PM
Post #1


Super Member
Group Icon

Group: [HOSTED]
Posts: 533
Joined: 25-April 05
Member No.: 4,374



A new service run by WSLabi (http://www.wslabi.com/wabisabilabi/home.do?) touts itself as the new eBay of vulnerability researchers (http://www.securityfocus.com/brief/542?ref=rss). From many years there has been a battle between security researchers and software publishers over the price or value of an exploit. As a researcher myself I know how many countless hours go into finding and developing material that is useful in making an exploit. I could easily turn it into a full time job. I do it for a hobby but what if someone wants to make it into a full time job? If you were only able to publish two or three really good exploits a year then you will have to get a fairly large price for you labors.

WSLabi makes it possible to ask the highest bidding price for your exploits. It is apparent that this site may encounter legal issues but these questions will have to be answered as this business model turns into a reality.

As a bonus to this story, one of the first exploits on the site is for a Yahoo! Messenger 8.1 vulnerability (ZD-00000005 - Yahoo! Messenger 8.1 remote buffer overflow). Very little information is given for the exploit but from the description it appears to have something to do with the address book. The current asking price starts at 2000 Euros which no one has taken yet. I am interested in seeing what this is but 2000 Euros is a tad bit high for my curiosity. If anyone is interested in creating an office pool for this exploit let me know. I am good for 50 Euros right now.
Go to the top of the page
 
+Quote Post
Alegis
post Jul 11 2007, 11:40 AM
Post #2


Premium Member
Group Icon

Group: Members
Posts: 300
Joined: 25-May 06
Member No.: 13,654



Interesting, didn't bother to look up yet how this did work. It does sound a bit like extortion or rather black-mail. Sure, QA of said program should be able to figure it out and protect it. If some people want to turn it into a full time job, they have to be prepared, not every job is in the right place or has demand for.

What use will the address book have? Might be something mundane or meaningless, or not relevant at all. I wouldn't waste money on things like that at all - Don't think it's even for use of those with evil intentions. I think your curiosity will get very disappointed.
Go to the top of the page
 
+Quote Post
Jimmy89
post Jul 11 2007, 11:57 AM
Post #3


Living at the Datacenter
Group Icon

Group: [HOSTED]
Posts: 696
Joined: 30-June 06
From: Australia
Member No.: 14,219



I must agree! I don't think I would want to go spend my money on something like an exploit, that by the time the 'auction' has finished, may have already ben resolved by Yahoo! And how do you know that they are telling the truth, they may just be making it all up!
Go to the top of the page
 
+Quote Post
tansqrx
post Jul 11 2007, 07:32 PM
Post #4


Super Member
Group Icon

Group: [HOSTED]
Posts: 533
Joined: 25-April 05
Member No.: 4,374



The thought of a scam or someone just making it up did run across my mind. I suppose what I would be more afraid of is a previously released exploit disguised as a new one. At any rate I feel that 50 Euros would be an acceptable price to pay for my curiosity.
Go to the top of the page
 
+Quote Post
Jimmy89
post Jul 12 2007, 04:28 AM
Post #5


Living at the Datacenter
Group Icon

Group: [HOSTED]
Posts: 696
Joined: 30-June 06
From: Australia
Member No.: 14,219



I suppose, but now all you need is another 39 people to share your curiosity so you can have a look at this exploit!
Go to the top of the page
 
+Quote Post
Jimmy89
post Jul 14 2007, 10:18 AM
Post #6


Living at the Datacenter
Group Icon

Group: [HOSTED]
Posts: 696
Joined: 30-June 06
From: Australia
Member No.: 14,219



I think your post should be more then just 'what?' to get your point across. But for your sake, whats happening is a group of people are trying to auction off exploits to the yahoo messenger program!
Go to the top of the page
 
+Quote Post
tansqrx
post Jul 23 2007, 04:43 PM
Post #7


Super Member
Group Icon

Group: [HOSTED]
Posts: 533
Joined: 25-April 05
Member No.: 4,374



Don’t worry, I completely understand that an exploit was being offered. From what I can tell the exploit was never bought because it is not showing up in the history. I guess 2000 Euro is a little more than anyone is willing to pay for a Messenger exploit.
Go to the top of the page
 
+Quote Post
Alegis
post Jul 24 2007, 11:38 AM
Post #8


Premium Member
Group Icon

Group: Members
Posts: 300
Joined: 25-May 06
Member No.: 13,654



And even then could have been something like "Doing this and this, you can add the same person twice in your addressbook!".
Don't pay too much of a price for curiosity, for there are many 'secrets',mysteries and things that just are but untold to others in the world tongue.gif

Well another reason for them not selling is their vague description. It doesn't seem of much use to anyone.
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Yahoo Messenger 7.0(10)
  2. Yahoo! Messenger Protocol Tutorial - Part 2(2)
  3. Yahoo! Messenger Protocol Tutorial - Part 3(0)
  4. Yahoo! Messenger Protocol Tutorial - Part 4(0)
  5. Yahoo! Messenger Protocol Tutorial - Part 5(0)
  6. Yahoo! Messenger Protocol Tutorial - Part 6(0)
  7. Yahoo! Messenger Protocol Tutorial - Part 7(0)
  8. Messenger Stealth Settings Bug?(2)
  9. Yahoo! Messenger Plugin Sdk(3)
  10. Yahoo! Messenger Through Web(6)
  11. New Yahoo! Messenger Protocol Changes?(4)
  12. New Yahoo! Web Messenger(12)
  13. The Yahoo! Messenger Zero-day For The Month Of August(1)
  14. “discovr” New Friend With Yahoo! Messenger(2)
  15. Messenger Mail Bug?(2)
  1. Minor Updates To Yahoo! Messenger Web(1)
  2. Yahoo! Messenger Author’s New Security Book(0)
  3. Yahoo! Messenger 9 Beta Preliminary Review(13)
  4. Tapping Yahoo! Messenger Phone Conversations(4)
  5. Hacking Yahoo! Messenger(12)
  6. Latest Yahoo! Vulnerability Appears To Be A Moving Target For Messenger(2)
  7. It Still Looks Like Microsoft Messenger May Still Happen(9)
  8. Yahoo! Messenger Talking To Google Talk?(7)
  9. Yahoo! Messenger Power User(1)
  10. Yahoo! Messenger Challenge Response Algorithm(11)


 



- Lo-Fi Version Time is now: 11th October 2008 - 05:08 AM