4 ms·
Friend just disclosed a 7 vuln chain RCE in a Fortune20 company. Affected all cloud and on-prem versions. They denied it as it was under NDA during a "schedule
by Mandatum 4y ago
Friend just disclosed a 7 vuln chain RCE in a Fortune20 company. Affected all cloud and on-prem versions.
They denied it as it was under NDA during a "scheduled" pentest (their client paid them to pentest and they alerted the vendor letting them know they'd be doing it during a 2 week period like most cloud vendors).
For someone to spend weeks developing that many vulnerabilities to get an RCE and then get nothing from the vendor other than "haha technically we don't have to pay you" - there is zero reason to not go through agencies that sell to governments (ZDI, Zerodium, etc).
You'll get paid and now the bug won't get patched.
Congratulations vendor, you played yourself.
- rtpg 4y agoI feel like all these takes seem to not really consider the idea that some people enjoy security work but do not want to be part of criminal enterprises, especially in the age of ransomware. Gaming devices have always been special I think cuz basically every heavy gamer pirates games as a kid (no money!) and there’s a very legit “I just want my device to run software” feeling, but I think generally people want shit to be fixed.
- feduphackers 4y agoThere’s another path - open source disclosure. I’m not seeking pay, I’m not using it. I’m just putting it right out there in the open. Should the wrong parties abuse it, oh well. At this point in life, I feel “responsible disclosure” is just a PR tool for shit-birds to use to dodge accountability. The only thing they will respond to is pain.
- rtpg 4y agoI do not understand the "oh well if it gets exploited" vibe. It's not the company that suffers in that case, but users of the software! Now, you might want to somehow tell these users about this, so they can get off of the software. And there's this balancing act in that case... In the abstract universe where I have a nasty exploit and the company wants to ignore it, I suppose I would just try to loudly publish a first step which is like "hey, I have this PoC which gives me RCE with this software, and the company is ignoring it", without revealing the methodology at first. Perhaps at least publishing some mitigation strategies. I am not a security researcher, but I understand that this would be hard. But I think it's not honest to say that just dumping an exploit to the world is the best alternative to stonewalling.
- vlovich123 4y agoSometimes, but not always, the stock market reacts by tanking the stock price. So the company does sometime get punished. For some vulnerabilities the end user does still end up paying more anyway though.
- Mandatum 4y agoA hack has never impacted the stock price for a company for more than a week. Look at Equifax, it had almost doubled it's stock price between 2017 and 2022. That company should be dead. Sony, Deloitte, Marriott, Tumblr, Disney, Maersk.. There's no repercussions for companies who are hacked. Until GDPR style fines are dealt, and companies are taken out back by regulatory agencies and shot - this will continue.
- rasz 4y agoThe thing you miss is CIO DGAF because he has paper trial covering his ass - pays for all kinds of corporate placebos (antivirus, waf), even did a pentest. Worst case scenario they will get in the news and get free advertising to >50% of clueless population.
- yardstick 4y agoI’m a bit confused by who is doing what. Can you clarify? Was your friend the one paid to do the pentest? And during that 2 week period your friend was doing the pentest they found the 7 vuln chain RCE? Or did they find the vulns during a period in time someone else was pentesting the company?
- tgsovlerkhgsel 4y agoMy understanding: There's three parties: 1. Cloud service provider, 2. Client, 3. Tester Client pays Tester to find vulns in Client's setup, including third party tools used by Client. Client notifies Cloud that there will be testing, and presumably the ToS allow such pentesting. In the process Tester discovers vulns in Cloud. The AWS rules are complicated https://aws.amazon.com/security/penetration-testing/ https://aws.amazon.com/security/penetration-testing/, for Google Cloud, you don't need to notify https://support.google.com/cloud/answer/6262505?hl=en#zippy=%2Cdo-i-need-to-notify-google-that-i-plan-to-do-a-penetration-test-on-my-project https://support.google.com/cloud/answer/6262505?hl=en#zippy=..., Microsoft used to require notification but no longer does https://docs.microsoft.com/en-us/azure/security/fundamentals/pen-testing https://docs.microsoft.com/en-us/azure/security/fundamentals... and seems to allow pentesting their services as long as you don't DoS them or exploit found vulnerabilities beyond a proof of concept.
- dx034 4y agoNot sure how to think about that. I'd expect a pen tester to live of the money they get for the pentest and not make extra money with bounties from the time spent during that pentest. If the bug was in the software of another vendor then that's not as clear, but I'm still not sure if the pentester should be entitled to a bounty. If anything, maybe the client should get the bounty as they hired and paid for the pentester to find vulns?