6类顶级黑客大盘点
漏洞经纪人 身份:Endgame公司,Netragard公司,Vupen公司 目的:把黑客行为当成合法生意 目标:未可知 特征:找到所谓的“零天攻击”代码(zero-day exploit)——即攻击新软件的方法,再把它们卖给政府和其他财大气粗的客户。 经典案例:去年3月举行的一次安全会议上,法国公司Vupen黑掉了谷歌公司(Google)的Chrome浏览器。这家公司并没有(收下6万美元,)把这项技术和谷歌分享,而是把代码卖给了出价更高的客户。 |
6. Vulnerability Broker Who: Endgame, Netragard, Vupen Objective: Hacking as legitimate business Targets: Agnostic Signature: Finding so-called zero-day exploits -- ways to hack new software, selling them to governments and other deep-pocketed clients Classic Case: French firm Vupen hacked Google's (GOOG, Fortune 500) Chrome browser at a security conference last March. Rather than share its technique with the company (and accept a $60,000 award), Vupen has been selling the exploit to higher-paying customers. |