- Автор темы
- Добавить закладку
- #21
With thorough consideration of all the productive remarks in the discussion earlier there is a new updated advertisement.
An exploit for a 0-day Unauthenticated RCE type vulnerability is for sale targeting a family of VPN/firewall/router devices of business/corporate level (according to the manufacturer's specification the top model in the family is capable of serving up to 500 simultaneous connections).
The exploit allows execution of arbitrary commands on the affected devices with the highest local permissions.
The exploit success rate is 9 of 10 randomly selected targets.
Passwords in the affected systems are stored in clear text.
Besides me the vulnerability was found by someone else and has been used in the wild. Nevertheless the vulnerability hasn't been disclosed yet, no CVE or any other identifiers assigned to it, there is no info or description of any kind, no public exploits, no fixes.
In order to avoid any leakage of information about the new vulnerability and thus the following fixup for it the details of the vulnerable devices such as "manufacturer-family-model-firmware" are disclosed either after the deal is sealed (the exploit itself) or if the buyer's reputation (registration date, activity, deals, recommendations, deposit, themes of the discussions) is good enough for the seller. Another option for the buyer is to invite a guarantor with the suitable reputation.
Approximate amount of potentially vulnerable targets split by countries and regions:
European Union:
2515 - United Kingdom
1267 - Portugal
1217 - Netherlands
585 - Poland
564 - Spain
393 - Germany
370 - Italy
244 - France
63 - Belgium
46 - Switzerland
46 - Ireland
40 - Sweden
36 - Denmark
31 - Norway, Luxembourg, Iceland, Austria
155 - Greece, Slovakia, Hungary, Slovenia
58 - Czech Republic, Finland, Romania, Croatia
US and alike:
200 - United States
172 - Australia, Canada, New Zealand
385 - Mexico
Middle East:
209 - Turkey
132 - Israel
73 - United Arab Emirates
49 - Saudi Arabia
25 - Egypt
26 - Bahrain, Jordan, Kuwait, Oman
Asia:
3316 - Vietnam
1920 - Taiwan
862 - Hong Kong
350 - China
114 - Thailand
122 - Malaysia, Singapore, Macao
54 - Philippines, Indonesia
30 - Brunei, South Korea
27 - Sri Lanka, Myanmar, India, Cambodia
South America:
215 - Brazil, Argentina
41 - Colombia, Chile, Venezuela, Ecuador
Having published the list above the seller assumes no obligations in any form. The list is solely for information purpose. During the deal sealing the buyer can request the seller to check the number of vulnerable devices in the countries specified by the buyer (up to 10 countries). The checking process will be done in manual mode on search engines Shodan, Censys without registration and/or login/password.
There are only two copies of the product available. The price for each is $50k. If a buyer needs to be the only buyer of the product they can purchase both copies paying full price for each (discount is possible). There are 0 copies sold at the moment. The number of copies sold can be tracked by the site's moderators I assume. Reselling is strictly forbidden.
All the deals will go through the site's escrow service of course.
An exploit for a 0-day Unauthenticated RCE type vulnerability is for sale targeting a family of VPN/firewall/router devices of business/corporate level (according to the manufacturer's specification the top model in the family is capable of serving up to 500 simultaneous connections).
The exploit allows execution of arbitrary commands on the affected devices with the highest local permissions.
The exploit success rate is 9 of 10 randomly selected targets.
Passwords in the affected systems are stored in clear text.
Besides me the vulnerability was found by someone else and has been used in the wild. Nevertheless the vulnerability hasn't been disclosed yet, no CVE or any other identifiers assigned to it, there is no info or description of any kind, no public exploits, no fixes.
In order to avoid any leakage of information about the new vulnerability and thus the following fixup for it the details of the vulnerable devices such as "manufacturer-family-model-firmware" are disclosed either after the deal is sealed (the exploit itself) or if the buyer's reputation (registration date, activity, deals, recommendations, deposit, themes of the discussions) is good enough for the seller. Another option for the buyer is to invite a guarantor with the suitable reputation.
Approximate amount of potentially vulnerable targets split by countries and regions:
European Union:
2515 - United Kingdom
1267 - Portugal
1217 - Netherlands
585 - Poland
564 - Spain
393 - Germany
370 - Italy
244 - France
63 - Belgium
46 - Switzerland
46 - Ireland
40 - Sweden
36 - Denmark
31 - Norway, Luxembourg, Iceland, Austria
155 - Greece, Slovakia, Hungary, Slovenia
58 - Czech Republic, Finland, Romania, Croatia
US and alike:
200 - United States
172 - Australia, Canada, New Zealand
385 - Mexico
Middle East:
209 - Turkey
132 - Israel
73 - United Arab Emirates
49 - Saudi Arabia
25 - Egypt
26 - Bahrain, Jordan, Kuwait, Oman
Asia:
3316 - Vietnam
1920 - Taiwan
862 - Hong Kong
350 - China
114 - Thailand
122 - Malaysia, Singapore, Macao
54 - Philippines, Indonesia
30 - Brunei, South Korea
27 - Sri Lanka, Myanmar, India, Cambodia
South America:
215 - Brazil, Argentina
41 - Colombia, Chile, Venezuela, Ecuador
Having published the list above the seller assumes no obligations in any form. The list is solely for information purpose. During the deal sealing the buyer can request the seller to check the number of vulnerable devices in the countries specified by the buyer (up to 10 countries). The checking process will be done in manual mode on search engines Shodan, Censys without registration and/or login/password.
There are only two copies of the product available. The price for each is $50k. If a buyer needs to be the only buyer of the product they can purchase both copies paying full price for each (discount is possible). There are 0 copies sold at the moment. The number of copies sold can be tracked by the site's moderators I assume. Reselling is strictly forbidden.
All the deals will go through the site's escrow service of course.
Последнее редактирование: