Hello folks, since we received a lot of questions about the whole marketplace procedure we'd like to point out some of our policies.
First thing, the researcher needs to sign up to our website: from this point on he can start submitting his work to the lab.
Please note that before selling anything, he'll be asked to fax or email his ID card details and a landline phone number, that we'll use to verify his identity.
We usually need full details about a vulnerability, so we might start a direct correspondence with the researcher, if necessary. Every communication is encrypted with PGP/GPG (here's our public key).
Once we get all the required details we can start testing the vulnerability.
Even if we are doing our best to speed up this part of the process it still requires some days: you can help us by sending as much information as you have about the vulnerability, i.e. debugger output, commented proof of concepts and step-by-step methods to trigger the vulnerability, in case it's a complicated vulnerability to exploit.
Despite our dedicated entry in our F.A.Q. page we are often asked which vulnerabilities we will accept or reject:
- all vulnerabilities related to network services, network clients, standalone clients, web applications and network devices are accepted and tested.
- we DO NOT accept vulnerabilities in specific websites, like for example eBay, Gmail, Hotmail, online casinos etc.
Once the vulnerability has been tested and accepted, we decide a starting price and a selling strategy together with the researcher, who will then receive our NDA. This must be returned signed, via fax or mail.
At this point we are ready to publish the vulnerability.
When the vulnerability is sold we will pay the researcher via paypal to his verified account or via wire transfer to his bank account.
If you want to be a bidder all you have to do is subscribe to our portal and provide the papers required to check and verify your identity. Please note that we only accept payments coming from a verified bank account in your name.
That's all.
Our purpose is raising awareness and reducing risk and contributing to the research of new vulnerabilities by both helping and protecting researchers and giving them appropriate compensation for their amazing work.
11/30/2007
WabiSabiLabi Walkthrough
Posted by
WabiSabiLabi Staff
at
4:24 PM
1 comments
11/28/2007
Quicktime zeroday vulnerability still zeroday
This morning we opened our favourite RSS reader and we found out a post about one of the vulnerabilities in our marketplace, the Quicktime client-side vulnerability.
As reported by Errata Security Blog, during the last few days some exploit codes for a Quicktime vulnerability have been posted.
What they say about one of the POC is:
"An interesting note is the most robust of the exploits makes a derogatory mention of WabiSabiLabi Labs, the exploit auction site. WabiSabiLabi has a QuickTime exploit for sale now that lists QuickTime 7.2 and Windows XP as the targets. You have to wonder if this is another case of a researcher using vague details to find the same vulnerability."
We just want to specify that the vulnerability shown on those POCs IS NOT the one present in our marketplace.
So, if you are interested in receiving some more details about the vulnerability we proposed don't hesitate to contact us and if you are interested in buying it, make a bid!
Posted by
WabiSabiLabi Staff
at
2:07 PM
2
comments
11/15/2007
Focus on: ClamAV remote code execution
From today on we will periodically talk about one of the most interesting vulnerabilities present in our marketplace.
Of course, we won’t disclose any technical details on how to reproduce or exploit the vulnerability, we will just give a brief description of it and, most of all, we will describe the impact that it may have on an enterprise and/or home environment.
Today we will discuss about a new ClamAV vulnerability.
As most of you know, ClamAV is an “open source (GPL) anti-virus toolkit for UNIX, designed especially for e-mail scanning on mail gateways”. It provides also a set of utilities, like for example a daemon and a command line scanner.
It has been recently submitted to our labs a vulnerability that allows a malicious user to execute arbitrary code on the machine running one of the utilities of the ClamAV suite by simply sending a specially crafted email to the vulnerable mailserver. You can bid on it HERE .
The latest verified vulnerable version is 0.91.1 but other versions could be affected as well (UPDATE: after further tests we can confirm that also 0.91.2 is vulnerable).
As you can obviously imagine, the impact of this vulnerability is ravaging.
ClamAV is used on almost every enterprise mail system based on Linux/Unix. When exploited, this vulnerability allows an attacker to execute arbitrary code on the target machine in the context of the user running the affected application and to have a “base” on the local network / DMZ, thus having the possibility to escalate privileges (if needed) and compromise other servers nearby the attacked one.
Of course, as it’s an antivirus engine designed for mailservers, the attacker can locally escalate his privileges and get access to all the mail traffic to and from the company just by sniffing the traffic on the compromised machine.
In a home scenario, even if ClamAV is not widely used in such environment, the impact can also be high. If a home computer is compromised, the attacker can access documents and files stored on that computer and use these informations to gain higher privileges.
The included PoC works very reliably.
This vulnerability has a starting price of 500 euros: bid on that and, as a security company, you will gain a very high competitive advantage.
Posted by
WabiSabiLabi Staff
at
4:41 PM
0
comments