anuseems Posted November 24, 2012 Share Posted November 24, 2012 Some companies, and individuals, find and disclose vulnerabilities -- may those be on websites, operating systems, programs, whatever -- for the betterment of society. Others do it for a "finder's fee". VUPEN does it so they can sell the secrets to whomever wants them.VUPEN is a security research firm that works a bit differently than other firms. Like traditional digital security firms, VUPEN does research on vulnerabilities on popular software packages (e.g. Windows). Unlike other firms, VUPEN does not disclose the vulnerabilities it finds. Rather, VUPEN offers the details of the vulnerabilities it finds to whomever is willing to pay the price. Yes, that is what it sounds like -- VUPEN sells vulnerabilities to the high bidders (so to speak).Of course the idea behind VUPEN is to make parties pay to better protect themselves; ideally the exploit secrets VUPEN sell are used by the buyers to protect themselves against the vulnerabilities. In reality, however, it isn't hard to imagine VUPEN-discovered vulnerabilities being bought for use in less legitimate activities, including but not limited to malware creation.The latest claim coming out VUPEN is that they have successfully found an exploit for Microsoft's Windows 8 and Internet Explorer 10: We welcome #Windows8 with various 0Ds combined to pwn all new Win8/IE10 exploit mitigations. Congrats to our mitigation mitigator @n_joly -VUPEN CEO Chaouki Bekrar on TwitterOf course it is impossible to confirm VUPEN's claim without shelling out the money to grab the details about the exploit(s) they have found in Microsoft's latest creations. However, I doubt VUPEN would risk its reputation making false claims. Plus exploits are nothing new in the tech industry, and it was only a matter of time before somebody hacked Windows 8. Why not it be VUPEN, a company that has great financial motive for doing so?Since Microsoft has not been informed about the vulnerability by VUPEN, Microsoft obviously cannot patch it. According to Microsoft's spokeperson: We saw the tweet, but further details have not been shared with us. We continue to encourage researcher to participate in Microsoft’s Coordinated Vulnerability Disclosure program to help ensure our customers’ protection.Uh-oh. A vulnerability in Windows 8 that will not be patched? Another reason to not buy Windows 8, right? Hang on there, cowboy.It should be noted that the Windows 8 and IE 10 vulnerability VUPEN claims to have found is unlikely to be exploited in the wild. This is because VUPEN utilized previously discovered but undisclosed vulnerabilities to come to this new vulnerability. So unless some scumbag purchases the vulnerability from VUPEN and releases it in the wild or someone figures out the vulnerability on their own (which is unlikely without them having access to the previous vulnerabilities), there is little risk to the average Joe from this particular vulnerability. Still, it has ramifications for Microsoft -- VUPEN discovered the vulnerability only a week after the release of Windows 8, and Microsoft has been advertising increased security in Windows 8 over previous Windows.It's definitely an interesting business VUPEN are in. Ideally every company should report exploits directly to Microsoft so they can work together to patch tit, but the reality is VUPEN makes money by not disclosing. Business is business, after all. Hopefully for Windows 8 users, this exploit doesn't get into the wrong hands.@ http://thenextweb.com/microsoft/2012/11/01/security-firm-vupen-claims-to-have-hacked-windows-8-and-ie10/ Link to comment Share on other sites More sharing options...
bigcid10 Posted November 25, 2012 Share Posted November 25, 2012 Don't worry if they don't hand it over to M$ then M$ will just buy them and dissolve them Link to comment Share on other sites More sharing options...
dcs18 Posted November 25, 2012 Share Posted November 25, 2012 My bet is on Windows 8 . . . . . . . to be hacked much more often. Link to comment Share on other sites More sharing options...
Administrator DKT27 Posted November 25, 2012 Administrator Share Posted November 25, 2012 My bet is on Windows 8 . . . . . . . to be hacked much more often. My bet is on it being hacked less often. Less users, less hacks. Windows 7 = old OS, more users, more hacks. Link to comment Share on other sites More sharing options...
rudrax Posted November 26, 2012 Share Posted November 26, 2012 Wanna here such thing regarding GNU/LINUX Link to comment Share on other sites More sharing options...
digimon Posted November 26, 2012 Share Posted November 26, 2012 Wanna here such thing regarding GNU/LINUXgnu/linux has 2 big advantages over windows the code is scoured by far more eyes caching bugs and around half as many users as windows 8 currently Link to comment Share on other sites More sharing options...
lurch234 Posted November 28, 2012 Share Posted November 28, 2012 I dont see any difference between this company and the authors of those "ransomware" trojans!And they should be dealt with accordingly! I consider this an indirect attempt at blackmail!Either you pay us or take the risk of having an exploit going up your tushy! :angry: Link to comment Share on other sites More sharing options...
Eternal X Posted November 29, 2012 Share Posted November 29, 2012 Windows 7 = Popular; Mac OSX = Popular; Android = Popular; iPhone = PopularPopular = More exploitation Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.