ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

iDefense offers bounty for Vista and IE7 flaws

Tom Espiner ZDNet.co.uk

Published: 11 Jan 2007 16:44 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security intelligence and analysis company iDefense is to offer an $8,000 bounty for vulnerabilities found in Vista and Internet Explorer 7 (IE7).

iDefense, which became part of Verisign in July 2005, is offering the cash as part of its Vulnerability Contributor Program (VCP), which pays researchers who provide iDefense with advance notification of unpublished vulnerabilities and/or exploit code.

The offer, which is running as part of iDefense's Q1 2007 vulnerability challenge until 31 March, 2007, is that iDefense will pay $8,000 (£4,117) for news of each submitted vulnerability that allows an attacker to remotely exploit and execute arbitrary code on fully patched default versions of Vista or IE7.

iDefense will award no more than six payments of $8,000 for vulnerabilties. In addition, the company is offering $2,000 to $4,000 for working, non-malicious exploits for the flaws. According to Trend Micro, exploits for Vista sell on the black market for up to $50,000.

iDefense is offering the rewards due to concerns among the security community over Microsoft's latest operating system and browser, the company said.

"Both Microsoft Internet Explorer and Microsoft Windows dominate their respective markets, and it is not surprising that the decision to update to the current release of Internet Explorer 7 and/or Windows Vista is fraught with uncertainty," said iDefense in a statement. "Primary in the minds of IT security professionals is the question of vulnerabilities that may be present in these two groundbreaking products," the announcement continued.

Microsoft said it was aware of iDefense offering compensation for information regarding security vulnerabilities, but did not condone the method of offering flaw bounties. "Microsoft does not offer compensation for information regarding security vulnerabilities and does not encourage that practice. Our policy is to credit security researchers who report vulnerabilities to us in a responsible manner," the company said in a statement.

iDefense's VCP, like TippingPoint's Zero Day Initiative, is designed to reward exclusive disclosure of vulnerabilities and exploits — the exploit may not be immediately divulged to the affected vendor. In return the company gains control over disclosure and can update its own security products.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
30 out of 34 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

IT Analysts and Consultants - Workplace Technologies and Collaboration

In return for taking on a high level of responsibility, youll build deep market-relevant skills and be rewarded with a competitive compensation ...

CRM Incentive Compensation Management Consultants-00047339

CRM Incentive Compensation Management Consultants-00047339 Description CRM Sales Transformation Incentive Compensation Management Consultants ...

Vista programmer sought for Oxfordshire leading service firm

This is a unique role for a Vista programmer to join a leading distribution firm, which is based in Oxfordshire. Vista/Access applications. You will ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment