TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Million Dollar iOS9 Bug Bounty

95 点作者 FredericJ超过 9 年前

13 条评论

stirlo超过 9 年前
I for one actually feel much more secure knowing that iOS is so secure that $1 million is considered the public value of an exploit. Vupen bought flash zero days for $30,000 in the past so knowing that iOS exploits are now valued enough to attract this kind of bounty makes me much more confident script kiddies and scammers will not be able afford to attack me. And lets face it, we were never secure from the NSA in the first place...
评论 #10255118 未加载
评论 #10252506 未加载
Klathmon超过 9 年前
I might be missing something, but has there ever been <i>any</i> exploit (or string of simultaneous exploits) for iOS or android which meets all the criteria?<p>It must be through a text message or web page, it must be remote, reliable, silent, require no interaction, must be entirely comprised of 0-day exploits throughout the whole chain, must affect multiple architectures and all supported devices, and must bypass all security checks to allow full root access.
评论 #10252780 未加载
评论 #10252799 未加载
tptacek超过 9 年前
And all you have to do is sell your unicorn vulnerability to this company:<p><i>ZERODIUM customers are major corporations in defense, technology, and finance, in need of advanced zero-day protection, as well as government organizations in need of specific and tailored cybersecurity capabilities</i><p>The offer to buy RCE in PHPBB&#x2F;vBulletin is a nice touch.
评论 #10253025 未加载
评论 #10253062 未加载
评论 #10253196 未加载
eyeareque超过 9 年前
A million bucks for a iOS 9 vulnerability sounds nice. But is that worth having the death, imprisonment, or torture of possibly innocent people on your conscience? If a government is buying these vulns, there is no telling what they will do with them.
评论 #10271317 未加载
jjoe超过 9 年前
Is this a Zerodium ad masquing the politically incorrect PR of &quot;zerodium has 0day exploits available for sale&quot;? I mean how else would anyone advertise availability of 0day without compromising their credibility? $1M per exploit would sure get you lots of press.
评论 #10252853 未加载
soared超过 9 年前
&quot;The whole exploitation&#x2F;jailbreak process should be achievable remotely, reliably, silently, and without requiring any user interaction except visiting a web page or reading a SMS&#x2F;MMS (attack vectors such as physical access, bluetooth, NFC, or baseband are not eligible for the Million Dollar iOS 9 Bug Bounty. ZERODIUM may, at its sole discretion, make a distinct offer to acquire such attack vectors.).&quot;<p>Can someone explain this part? Jailbreak from a website, sms, or mms seems ... impossible. Has this even been possible with older jailbreaks?
评论 #10252833 未加载
评论 #10252851 未加载
评论 #10252843 未加载
评论 #10252933 未加载
评论 #10252834 未加载
JoshTriplett超过 9 年前
I have to wonder: what stops someone from selling the &quot;exclusive&quot; rights to an exploit, waiting for the check to clear, and then disclosing it privately to the vendor to get fixed?
评论 #10252677 未加载
评论 #10271327 未加载
ins0超过 9 年前
<i>The exploit&#x2F;jailbreak must support and work reliably on the following devices (32-bit and 64-bit when applicable): - iPhone 6s &#x2F; iPhone 6s Plus &#x2F; iPhone 6 &#x2F; iPhone 6 Plus - iPhone 5 &#x2F; iPhone 5c &#x2F; iPhone 5s - iPad Air 2 &#x2F; iPad Air &#x2F; iPad (4rd generation) &#x2F; iPad (3th generation) &#x2F; iPad mini 4 &#x2F; iPad mini 2</i><p>So did i read this correct and the exploit must be backwards compatible in order to get the full bounty?
评论 #10252484 未加载
评论 #10252511 未加载
halestock超过 9 年前
off topic, but wow it&#x27;s really annoying that the site overrides your scroll-speed settings.
评论 #10254629 未加载
ck2超过 9 年前
Has anyone tried a really long password ;-)
评论 #10253813 未加载
评论 #10253951 未加载
lawnchair_larry超过 9 年前
Sounds like ios8 will be the last jailbreakable version. Shame.
评论 #10252864 未加载
评论 #10252726 未加载
评论 #10254167 未加载
评论 #10255494 未加载
评论 #10253919 未加载
fla超过 9 年前
Saurik, you can do it ;)
myohan超过 9 年前
What they&#x27;re not telling you is finding this exploit entails NP=P. It sure has the same bounty value on its head. jk