3 ms·
I'm not too sure that's the business VUPEN is in. Sure, it doesn't hurt them much to share their latest Safari exploit given how slow Apple is on the fix, but w
by trotsky 15y ago
I'm not too sure that's the business VUPEN is in. Sure, it doesn't hurt them much to share their latest Safari exploit given how slow Apple is on the fix, but with Google their window has the potential to be very short.
- tlb 15y agoCitation needed for such a serious accusation. They claim to be ethical. From their about page: "VUPEN follows a private responsible disclosure policy and reports all discovered vulnerabilities to the affected vendor under contract with VUPEN, and works with them to create a timetable pursuant to which the vulnerability information may be publicly disclosed."
- ceejayoz 15y agohttp://www.vupen.com/english/services/ http://www.vupen.com/english/services/ > As the world leader in vulnerability research, VUPEN Security provides weaponized and highly sophisticated exploits specifically designed for Law Enforcement and Intelligence Agencies to help them achieve their offensive missions using tailored and unique codes created in-house by VUPEN for vulnerabilities discovered by our researchers. Note also the "under contract with VUPEN" part of the disclosure bit.
- chopsueyar 15y agoLaw Enforcement and Intelligence Agencies Which countries? It does not specifically state US.
- trotsky 15y agoI'm pretty sure they limit their customer base to NATO signatories.
- chopsueyar 15y agoLink?
- trotsky 15y agoWell, I was close... - Gov. and Law Enforcement Agencies in Countries Members or Partners of NATO, ANZUS or ASEAN http://www.vupen.com/english/services/ba-gov.php http://www.vupen.com/english/services/ba-gov.php
- caf 15y agoASEAN includes such well-known liberal democracies as Burma, Vietnam, Laos and Brunei.
- dsl 15y ago"With 20 to 25 binary analysis and private exploits/PoCs released each month, the VUPEN In-Depth Binary Analysis and Exploits service allows organizations and corporations to evaluate and qualify risks, and protect national infrastructures and corporate assets from emerging attacks." If you are interested in protecting your network, patches and workarounds are your first priority, not "proof of concept" exploits.
- tptacek 15y agoDo you do a lot of in-the-field security work? How do you work around a vulnerability without being able to see whether and how it works?
- uxp 15y agoIf VUPEN found the vulnerability, the work around is to pay VUPEN in order to patch your codebase. Pretty simple, theoretically. If you don't have access to the codebase (like a Safari or MSIE bug), then you pay VUPEN to disclose a firewall filter, or some other kind of deep packet inspection to disallow the code required to execute the vulnerability on your network. Again, pretty simple, in theory. VUPEN plays a pretty tight game. The only way to get in on their action is money. You know this though, and I doubt our opinions differ on the matter. Unlike opensource, full-disclosure GitHub junkies, some people find enjoyment in financially benefiting on everything they stumble across. Just another side of the coin, and the argument about that topic is best left for other sites. :)
- daniel_solano 15y agoJust relying off the quote given: "VUPEN follows a private responsible disclosure policy and reports all discovered vulnerabilities to the affected vendor under contract with VUPEN…" It makes it sound like if they crack your software, you only get disclosure if you are paying them money. However, I could be wrong.
- trotsky 15y agoChaouki Bekar, VUPEN’s CEO and head of research, confirmed that the company had no plans to share any details about their findings with Google, nor was it aware of any steps users could take to mitigate the threat from this attack. “No, we did not alert Google as we only share our vulnerability research with our Government customers for defensive and offensive security,” Bekar wrote in response to an emailed request for comment. “Unfortunately, we are not aware of any mitigation to protect against these vulnerabilities.” http://krebsonsecurity.com/2011/05/security-group-claims-to-have-subverted-google-chromes-sandbox/ http://krebsonsecurity.com/2011/05/security-group-claims-to-...
- othermaciej 15y agoTo the best of my knowledge, VUPEN does not disclose vulnerabilities to the vendor affected unless the vendor is under contract with them and pays them. I have seen them post a public claim of a previously unknown vulnerability in one of my employer's products, and as far as I know they have never reported the details.