Results 1 to 2 of 2

Thread: New Java Exploit Fetches $5,000 Per Buyer

  1. #1
    Join Date
    May 2010
    Posts
    3,852
    Rep Power
    17

    Default New Java Exploit Fetches $5,000 Per Buyer

    Less than 24 hours after Oracle patched a dangerous security hole in its Java software that was being used to seize control over Windows PCs, miscreants in the Underweb were already selling an exploit for a different and apparently still-unpatched zero-day vulnerability in Java, KrebsOnSecurity has learned.

    javaredOn Sunday, Oracle rushed out a fix for a critical bug in Java that had been folded into exploit kits, crimeware made to automate the exploitation of computers via Web browser vulnerabilities. On Monday, an administrator of an exclusive cybercrime forum posted a message saying he was selling a new Java 0day to a lucky two buyers. The cost: starting at $5,000 each.
    https://krebsonsecurity.com/2013/01/...000-per-buyer/


  2. #2
    Join Date
    Oct 2006
    Posts
    9,074
    Rep Power
    27

    Default

    “New Java 0day, selling to 2 people, 5k$ per person

    And you thought Java had epically failed when the last 0day came out. I lol’d. The best part is even-though java has failed once again and let users get compromised… guess what? I think you know what I’m going to say… there is yet another vulnerability in the latest version of java 7. I will not go into any details except with seriously interested buyers.

    Code will be sold twice (it has been sold once already). It is not present in any known exploit pack including that very private version of [Blackhole] going for 10$k/month. I will accepting counter bids if you wish to outbid the competition. What you get? Unencrypted source files to the exploit (so you can have recrypted as necessary, I would warn you to be cautious who you allow to encrypt… they might try to steal a copy) Encrypted, weaponized version, simply modify the url in the php page that calls up the jar to your own executable url and you are set. You may pm me.”
    some serious money these people making from finding exploits

    http://krebsonsecurity.com/2013/01/c...-buying-spree/

    Last edited by semitop; Jan 16, 2013 at 12:46 PM.
    This posting is provided "AS IS" with no warranties, and confers no rights.
    You assume all risk for your use. © 2006 Azix Solutions.
    All rights reserved.

    Dropbox: http://db.tt/8qVS35lo

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •