Less than zero-day
[This was prepared the morning of October 1, but not posted because I expected more to come of the story rather quickly. It now appears [link to http://developer.mozilla.org/devnews/index.php/2006/10/02/update-possible-vulnerability-reported-at-toorcon/ no longer works] that 1. is true.]
OK, so at Toorcon a couple of guys — one of whom works at SixApart — reported [link to http://news.zdnet.com/2100-1009_22-6121608.html no longer works] on a Firefox 0day.
These gents claim to have another 30 vulns that they are going to hold onto.
That’s interesting. Mozilla offers a $500 bug bounty [link to http://www.mozilla.org/security/bug-bounty.html no longer works]. Therefore, I conclude that either:
- These guys do not have the 0days they claim to have, or
- They expect to get more than $500 for them elsewhere, or
- They dislike money
I find 3. hard to believe.
Ok, third-hand information but…
I heard from a friend of those individuals, and they say they were just joking. So, option 1.
Agreed, Mr. X. That’s what I was saying up top in the square brackets.
I’ve submitted a security critical bug to Mozilla and filed for a bug bounty, but have not received one. Do they actually pay up? If my experience is typical, that would explain the reluctance/apathy towards submitting further bugs.