6类顶级黑客大盘点
|
????漏洞经纪人 ????身份:Endgame公司,Netragard公司,Vupen公司 ????目的:把黑客行为当成合法生意 ????目标:未可知 ????特征:找到所谓的“零天攻击”代码(zero-day exploit)——即攻击新软件的方法,再把它们卖给政府和其他财大气粗的客户。 ????经典案例:去年3月举行的一次安全会议上,法国公司Vupen黑掉了谷歌公司(Google)的Chrome浏览器。这家公司并没有(收下6万美元,)把这项技术和谷歌分享,而是把代码卖给了出价更高的客户。 |
????6. Vulnerability Broker ????Who: Endgame, Netragard, Vupen ????Objective: Hacking as legitimate business ????Targets: Agnostic ????Signature: Finding so-called zero-day exploits -- ways to hack new software, selling them to governments and other deep-pocketed clients ????Classic Case: French firm Vupen hacked Google's (GOOG, Fortune 500) Chrome browser at a security conference last March. Rather than share its technique with the company (and accept a $60,000 award), Vupen has been selling the exploit to higher-paying customers. |

