6類頂級黑客大盤點
????漏洞經紀人 ????身份:Endgame公司,Netragard公司,Vupen公司 ????目的:把黑客行為當成合法生意 ????目標:未可知 ????特征:找到所謂的“零天攻擊”代碼(zero-day exploit)——即攻擊新軟件的方法,再把它們賣給政府和其他財大氣粗的客戶。 ????經典案例:去年3月舉行的一次安全會議上,法國公司Vupen黑掉了谷歌公司(Google)的Chrome瀏覽器。這家公司并沒有(收下6萬美元,)把這項技術和谷歌分享,而是把代碼賣給了出價更高的客戶。 |
????6. Vulnerability Broker ????Who: Endgame, Netragard, Vupen ????Objective: Hacking as legitimate business ????Targets: Agnostic ????Signature: Finding so-called zero-day exploits -- ways to hack new software, selling them to governments and other deep-pocketed clients ????Classic Case: French firm Vupen hacked Google's (GOOG, Fortune 500) Chrome browser at a security conference last March. Rather than share its technique with the company (and accept a $60,000 award), Vupen has been selling the exploit to higher-paying customers. |