Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 31 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Other
Bug Hunting
EH-Net
May 23, 2013, 08:46:11 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Other
(Moderator:
don
) >
Bug Hunting
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Bug Hunting (Read 5345 times)
0 Members and 1 Guest are viewing this topic.
delusion
Newbie
Offline
Posts: 49
Bug Hunting
«
on:
September 02, 2011, 04:08:42 PM »
Hey Hey Security Folk!
Its friday again and I am seeking something new to get my teeth stuck into. How rewarding would it be to find a bug in a system which I can redeem money from. YES yes there's no instant mind zip gaining the knowledge required to get started, but with that said I am looking of a place to start.
I understand there is this little thing called the internet, but in trust that's not how I do it, I want to know the pros thoughts on where to start and where better to do it, none other than my favourite forum.
Thoughts eth peeps?
Logged
You Cant Resolve Problems Whilst At WAR!
cd1zz
Hero Member
Offline
Posts: 561
Re: Bug Hunting
«
Reply #1 on:
September 03, 2011, 11:03:35 AM »
Big companies have bounty programs, like facebook and google. You could always sell your bugs to tippingpoint too.
However, you usually bug hunt because its enjoyable not because you'll get rich from it. When you add up the amount of time it takes to find a bug, determine if its exploitable, crafting a reliable exploit......the time adds up big time.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
delusion
Newbie
Offline
Posts: 49
Re: Bug Hunting
«
Reply #2 on:
September 03, 2011, 11:21:11 AM »
Hi cd1zz thanks for you input. They do indeed, am familiar with a lot of the common programs.
Just wondered if there were any bug hunters on here that could push me into the right starting direction.
My comment was that it would be nice to find an 0 day and get paid for it. I would be doing it for the passion of security, but incentives are as always embraced with open arms.
I really dont see the point of doing something just for the sake of doing it and although I do love money, if this is where my true motivations sat I would probably be gearing my roadmap more towards sales or stock markets. I just generally fancy trying something new and If i find a new bug, well then it would definitely look good on my CV.
Logged
You Cant Resolve Problems Whilst At WAR!
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Bug Hunting
«
Reply #3 on:
September 03, 2011, 11:37:38 AM »
There's also "hatforce.com", and possibly "uTest.com" as well, I'm not sure about uTest, as I haven't tried that fully yet. (I'm only interested in security jobs.) Hatforce.com is fairly new, but so far quite nice. Take a look from time to time, to see if there's any new projects
It sounds more like you should do research instead, write an awesome paper and presentation, then go to some conferences to talk about it and don't get sued too
(Depending on where you live of course.)
If you just want money for 0days, find some very good ones and sell them to e.g., ZDI, and so forth. This requires of course, pretty good skills I'd say as they don't accept all 0days, there's a list of products. (Other sites may accept them though.)
Good luck!
Logged
I'm an InterN0T'er
delusion
Newbie
Offline
Posts: 49
Re: Bug Hunting
«
Reply #4 on:
September 05, 2011, 07:10:02 AM »
Hi MaXe. Thanks very powerful thought! However there's a very long journey ahead, until something like that could even be considered to be brought into play. I definitely do like the sound of it however.
Good comments. Good pointers. Thanks for your time.
Logged
You Cant Resolve Problems Whilst At WAR!
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Bug Hunting
«
Reply #5 on:
September 05, 2011, 05:33:04 PM »
No problem, it's why I'm around
I should note however, that 99,9% of the work I do is voluntary (free), so don't expect good tips on how to make a lot of money from me, unless you have mad exploit research and development skills, then I know where you should go to
However, ZDI is worth it if you're that good:
http://www.zerodayinitiative.com/about/benefits/
At least, that's my opinion and no I don't have any affiliation with them, but it's one site I would probably sell exploits to if I had any of those they want
Logged
I'm an InterN0T'er
the_Grinch
Newbie
Offline
Posts: 45
Re: Bug Hunting
«
Reply #6 on:
September 05, 2011, 09:27:05 PM »
Question into the exploit creation, how to you go about doing further testing? Say I find what I believe is a bug and write the exploit for it. I can test it on a virtual machine locally, but is that enough of a test? Obviously, wherever you submit it will test it throughly, but is it possible to test it throughly yourself as well? In an ethical manner, as it were...
Logged
BS-CST Security+
Blog:
http://havewire.blogspot.com/
cd1zz
Hero Member
Offline
Posts: 561
Re: Bug Hunting
«
Reply #7 on:
September 05, 2011, 10:41:24 PM »
A couple pieces of advice for you:
If its a network exploit, meaning you send some malformed packet across the wire to a victim, make sure you test it by putting your victim and attacker machine on different subnets/IPs. On one of my exploits, the GoldenFTP 4.70 PASS exploit, I saw inconsistent behavior when changing the IPs. Someone else ended up figuring this piece out and making the exploit a bit more reliable. I have only seen this on two exploits I've done, so it's not that common I don't think.
Quote
Obviously, wherever you submit it will test it throughly, but is it possible to test it throughly yourself as well?
This is not true. Packetstorm for example will take anything, and not test it at all prior to posting. I have a few exploits on packetstorm that exploit-db did not take for one reason or another. Exploit-db will do some very basic testing, just to make sure your sploit works as advertised.
For further testing, you could design your exploit to work on different OS versions and service packs. Make sure you also reboot everything and run your exploit again etc..... just keep thinking of ways that would break your nice shiny exploit
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Bug Hunting
«
Reply #8 on:
September 06, 2011, 12:26:37 PM »
Quote from: cd1zz on September 05, 2011, 10:41:24 PM
Exploit-db will do some very
basic testing
, just to make sure your sploit works as advertised.
What you say?
(Aybabtu)
I know it isn't directly related to exploit development, in the terms you are referring to, but whenever there is a vBulletin exploit submitted I often do test it very thoroughly and confirm whether it works or not. (Including requisites for it to work.)
Logged
I'm an InterN0T'er
cd1zz
Hero Member
Offline
Posts: 561
Re: Bug Hunting
«
Reply #9 on:
September 06, 2011, 04:35:04 PM »
LOL - what I meant to say is that you guys wont be doing the dirty testing that the author should be doing. I'm certainly not diminishing all the verification that the exploit-db crew does. That is awesome that someone does go through and validate - other sites have a bunch of junk up there
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Bug Hunting
«
Reply #10 on:
September 06, 2011, 05:08:39 PM »
Quote from: cd1zz on September 06, 2011, 04:35:04 PM
LOL - what I meant to say is that you guys wont be doing the dirty testing that the author should be doing. I'm certainly not diminishing all the verification that the exploit-db crew does. That is awesome that someone does go through and validate - other sites have a bunch of junk up there
Ah
I can relate to that, especially with all the sweat and tears from crafting a Proof of Concept for a binary program
Or a really in-depth Web Application exploit that requires multiple vectors to work, but in return could give an attacker shell access
But yes, you're right that it's rarely they'd do that, unless they want to craft a more reliable exploit, recreate it for fun, or develop an exploit from a DoS PoC
Logged
I'm an InterN0T'er
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Greetings
: Hi from the UK
(3) by
UKSecurityGuy
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(2) by
n37sh@rk
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.