6類頂級(jí)黑客大盤點(diǎn)
????漏洞經(jīng)紀(jì)人 ????身份:Endgame公司,Netragard公司,Vupen公司 ????目的:把黑客行為當(dāng)成合法生意 ????目標(biāo):未可知 ????特征:找到所謂的“零天攻擊”代碼(zero-day exploit)——即攻擊新軟件的方法,再把它們賣給政府和其他財(cái)大氣粗的客戶。 ????經(jīng)典案例:去年3月舉行的一次安全會(huì)議上,法國(guó)公司Vupen黑掉了谷歌公司(Google)的Chrome瀏覽器。這家公司并沒有(收下6萬(wàn)美元,)把這項(xiàng)技術(shù)和谷歌分享,而是把代碼賣給了出價(jià)更高的客戶。 |
????6. Vulnerability Broker ????Who: Endgame, Netragard, Vupen ????Objective: Hacking as legitimate business ????Targets: Agnostic ????Signature: Finding so-called zero-day exploits -- ways to hack new software, selling them to governments and other deep-pocketed clients ????Classic Case: French firm Vupen hacked Google's (GOOG, Fortune 500) Chrome browser at a security conference last March. Rather than share its technique with the company (and accept a $60,000 award), Vupen has been selling the exploit to higher-paying customers. |