ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

TippingPoint to offer bug bounty

Joris Evers CNET News.com

Published: 25 Jul 2005 15:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Found a security bug? TippingPoint will pay you for the details.

TippingPoint — part of 3Com — is soliciting hackers to report vulnerabilities in exchange for money. If a valid bug is found, TippingPoint will notify the maker of the flawed product and update its security products to protect users against exploitation of the flaw until an official patch is released.

"We want to reward and encourage independent security research, promote and ensure responsible disclosure of vulnerabilities and provide 3Com customers with the world's best security protection," David Endler, director of security research at TippingPoint, said in an interview.

TippingPoint sells intrusion prevention systems, which are designed to protect against vulnerabilities, on servers, desktops and other computers connected to an organisation's network.

The payments are being offered under TippingPoint's new "Zero Day Initiative". The company plans to announce the programme on Monday and celebrate the launch with a party in Las Vegas on Wednesday, the first day of the annual Black Hat Briefings an event for security professionals and enthusiasts.

Few companies offer rewards for pinpointing software vulnerabilities. The rewards are almost always paid by security companies for flaws in other companies' software products. The payouts are used to gain a competitive edge over rivals by having their products recognize more vulnerabilities.

Security intelligence company iDefense, which was recently acquired by VeriSign, and the Mozilla Foundation also pay security researchers, or hackers. Mozilla offers $500 (£285) and a Mozilla T-shirt to those who find critical security flaws in its products, which include the Firefox Web browser.

Money has increasingly become an incentive for hackers. Program's such as TippingPoint's offer a legitimate way for them to get paid for their bug hunting. There is also an underground market for information on vulnerabilities. Cybercriminals pay top dollar for previously undisclosed flaws that they can then exploit to break into computer systems, experts have said.

Bugs can be reported to TippingPoint through the Zero Day Initiative Web site. TippingPoint investigates all reports and will deal only with reputable researchers, Endler said. "We need to know exactly who we are working with," he said. "We don't want to work with black hats or illegal groups." The term "black hat" is used to describe criminal hackers.

If a flaw is found to be genuine, TippingPoint will make an offer. The amount depends on the scope of the vulnerability. A problem that lets an attacker remotely access a computer will fetch more than a bug that could only crash a system, for example. If the researcher takes the offer, the rights to the bug report are signed over to TippingPoint, Endler said.

An unspecified time after protecting its own customers and before a fix is released, TippingPoint plans to share vulnerability details with other makers of intrusion prevention products. "We're making an altruistic gesture to protect a larger segment rather than just our customer base," Endler said.

Those who report flaws to TippingPoint will get credit for their discovery and can keep track of the status of the bug report through the Zero Day Initiative Web site, Endler said. A special reward programme makes it lucrative to contribute multiple vulnerabilities, he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
78 out of 131 people found this useful


Full Talkback thread

0 comments

Related Jobs

Service Delivery Manager - Lambeth, London, South East

PFI contract and a brand new 6 year BSF contract (government's flagship 'Building Schools for the Future initiative) to deliver ICT services to ...

Functional Analyst

Youll also have a can-do attitude, with the drive and initiative to play your part in an enthusiastic, motivated and energetic team. Functional ...

NIHR/UK Clinical Research Network

It also aims to develop and implement integrated research and development management systems that will support researchers and NHS administrators ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment