7 ms·
The and-httpd server has a $2,000 "security guarantee"
- steve19 14y agoThat page was last modified in 2006. It must have held up well against attacks or he would be broke by now!
- autotravis 14y ago"The $2,000 is only available to the first person who provides a working attack"
- dkhenry 14y agoI would look to find the last time the code was worked on, but there isn't even a code repository listed.
- andrewthornton 14y agoHere is the latest source for anyone with too much time on their hands: http://www.and.org/and-httpd/0.99.11/ http://www.and.org/and-httpd/0.99.11/ Last update from changelog is 2006-09-10
- naww 14y agoFiles missing.
- pandemicsyn 14y agoSimilar to the bounty Dovecot http://dovecot.org/security.html http://dovecot.org/security.html has.
- dpkendal 14y agoThis sort of thing is not new. I think the first one was qmail: http://cr.yp.to/qmail/guarantee.html http://cr.yp.to/qmail/guarantee.html followed shortly by djbdns: http://cr.yp.to/djbdns/guarantee.html http://cr.yp.to/djbdns/guarantee.html (which was awarded in 2009: http://article.gmane.org/gmane.network.djbdns/13864 http://article.gmane.org/gmane.network.djbdns/13864) Dovecot also has a similar guarantee: http://dovecot.org/security.html http://dovecot.org/security.html As does Mozilla: http://www.mozilla.org/security/bug-bounty.html http://www.mozilla.org/security/bug-bounty.html Even Facebook is in on the game: http://www.facebook.com/whitehat/bounty/ http://www.facebook.com/whitehat/bounty/ Bug bountying in general of course started with Donald Knuth: http://en.wikipedia.org/wiki/Knuth_reward_check http://en.wikipedia.org/wiki/Knuth_reward_check and has recently become moderately popular as a strategy for increasing open-source code quality: http://www.daemonology.net/blog/2011-09-05-lessons-learned-from-bountying-bugs.html http://www.daemonology.net/blog/2011-09-05-lessons-learned-f...
- tete 14y agoAnd Chromium: http://www.chromium.org/Home/chromium-security/vulnerability-rewards-program http://www.chromium.org/Home/chromium-security/vulnerability...
- dkroy 14y agoHow did this get to the front page when the last update to the source was 6 years ago?
- mitchi 14y ago+1
- duked 14y agoI wanted to give it a try, had to look for the source (found it on sourceforge) tried to ./configure it requires a Vstr from the same website now need to look for the source ... It's not like they want you to try it :D
- josephlord 14y agoThat isn't a guarantee it's a bounty. A guarantee would pay out to all affected customers. Affected probably would mean compromised by an attacker.