7 ms·
There are many incentives not to sell exploits, the major one being that it's not logistically feasible. First of all the people submitting these false reports
by snowmobile 9mo ago
There are many incentives not to sell exploits, the major one being that it's not logistically feasible. First of all the people submitting these false reports don't have any real exploits.
But imagine you were sitting on an actual RCE exploit in curl, who would you sell it to? How would you convince them it's working without disclosing the details for free? How would you get paid?
> Curl is a popular and well supported tool, if it needs help in this area, there will be a long line of competent people not volunteering their time and/or money
I'm not sure if that not is a typo, but yes, even though a tool is very popular, there's almost nobody competent and willing to work on it for free. This has been a well-known problem in open source for decades now.
- notepad0x90 9mo agoIt's a typo, even if they don't sell it why report it to curl? for clout? You can still exploit it against real world apps. Who would they sell it to? I would sell it to zerodium instead of report to curl personally. How much time do people spend finding bugs, is their time not worth anything because some other random people decide to use AI? Curl is high-visibility, there are people. and it doesn't take a lot of competency to triage. Heck, I like to think I have a good handle at C and memory exploitation, I will volunteer my time for free if they need help.