Jump to content

Microsoft gives you up to $15,000 USD if you find a security flaw in Spartan

GoodBytes

Microsoft is very serious with Spartan web browser.

It is offering a nice bounty up to $15,000 USD if you find a security flaw in the Spartan web browse.

The minimum is 500$. Basically, the more critical the security flaw is, and the more you provide details on how to reproduce it the more money you can get.

Microsoft says that if the flaw is really critical, the reward can be over $15,000

The program if only available for the Technical Preview of Windows 10. It begins 22 April 2015, and ends 22 June 2015. (so I guess we know when Windows 10 is expected to be released, now, more officially. My guess, July 1st to give them time to fix that critical error, if discovered/reported on the last day).

 

Microsoft is pleased to announce the launch of a vulnerability bounty program for Microsoft-branded internet browsers shipping with Windows 10 technical preview. The program begins 22 April 2015, and ends 22 June 2015. For the duration of the program, individuals across the globe have the opportunity to submit vulnerabilities found in Microsoft-branded internet browsers shipping on our latest pre-release Windows platform. Qualified submissions are eligible for payment from a minimum of $500 USD to $15,000 USD, and bounties will be paid out at Microsoft’s discretion based on the quality and complexity of the vulnerability. Microsoft may pay more than $15,000 USD, depending on the entry quality and complexity,

The details are that:

-> You need to be 14 years old or over

-> Needs to be previously unreported, including Remote Code Execution (RCE), Address Space Layout Randomization (ASLR) Information Disclosure Vulnerabilities, and Sandbox Escape Vulnerabilities

-> Explain in detail how to reproduce it (the more details, the better for you)

-> Cannot be a current employee or family related Microsoft employee

-> Cannot be in North Korea, Cuba, Iran, Sudan, and Syria, due to U.S sanctions

-> No companies. You need to be a person.

mstable.PNG

For full details: https://technet.microsoft.com/en-us/security/dn972323?f=255&MSPPError=-2147217396

Source: http://www.winbeta.org/news/windows-10s-project-spartan-microsoft-will-give-you-15000-usd-if-you-find-security-bugs

Link to comment
Share on other sites

Link to post
Share on other sites

hm. interesting... id like to find some >:D

~New~  BoomBerryPi project !  ~New~


new build log : http://linustechtips.com/main/topic/533392-build-log-the-scrap-simulator-x/?p=7078757 (5 screen flight sim for 620$ CAD)LTT Web Challenge is back ! go here  :  http://linustechtips.com/main/topic/448184-ltt-web-challenge-3-v21/#entry601004

Link to comment
Share on other sites

Link to post
Share on other sites

This is a very good idea on Microsoft's part. Cash incentives will get a lot of people to go and try to exploit the browser. I do believe this should include through-Windows exploits so those can also be patched.

Always trying to find reason.

Link to comment
Share on other sites

Link to post
Share on other sites

I love bug bounties. The alternative to paying out $15k+ for an exploit fix is the bad guys getting wind of this and causing big problems.

I do not feel obliged to believe that the same God who has endowed us with sense, reason and intellect has intended us to forgo their use, and by some other means to give us knowledge which we can attain by them. - Galileo Galilei
Build Logs: Tophat (in progress), DNAF | Useful Links: How To: Choosing Your Storage Devices and Configuration, Case Study: RAID Tolerance to Failure, Reducing Single Points of Failure in Redundant Storage , Why Choose an SSD?, ZFS From A to Z (Eric1024), Advanced RAID: Survival Rates, Flashing LSI RAID Cards (alpenwasser), SAN and Storage Networking

Link to comment
Share on other sites

Link to post
Share on other sites

I love bug bounties. The alternative to paying out $15k+ for an exploit fix is the bad guys getting wind of this and causing big problems.

exactly! It's either pay a white hat hacker $X or have a black hat exploit it and cause millions in damages, both to the victim(s) and to your own image

Case: NZXT Phantom PSU: EVGA G2 650w Motherboard: Asus Z97-Pro (Wifi-AC) CPU: 4690K @4.2ghz/1.2V Cooler: Noctua NH-D15 Ram: Kingston HyperX FURY 16GB 1866mhz GPU: Gigabyte G1 GTX970 Storage: (2x) WD Caviar Blue 1TB, Crucial MX100 256GB SSD, Samsung 840 SSD Wifi: TP Link WDN4800

 

Donkeys are love, Donkeys are life.                    "No answer means no problem!" - Luke 2015

 

Link to comment
Share on other sites

Link to post
Share on other sites

Awesome. Shame i'm not one who can find exploits in things :(

Case: Ncase M1 V5 Black CPU: Intel Core i5 12600 MB: AORUS Z690i RAM: 16GB Kingston HyperX DDR4 SSD: WD SN770 500GB | WD SN750 250GB

Cooler: Noctua NH-L9x65 GPU: EVGA RTX 3070 XC3 Ultra 8GB PSU: Corsair SF600 80+ Platinum Fans: Noctua NF-F12x 2 | Noctua NF-A9x14

Link to comment
Share on other sites

Link to post
Share on other sites

Nice :D

| Ryzen 7 7800X3D | AM5 B650 Aorus Elite AX | G.Skill Trident Z5 Neo RGB DDR5 32GB 6000MHz C30 | Sapphire PULSE Radeon RX 7900 XTX | Samsung 990 PRO 1TB with heatsink | Arctic Liquid Freezer II 360 | Seasonic Focus GX-850 | Lian Li Lanccool III | Mousepad: Skypad 3.0 XL / Zowie GTF-X | Mouse: Zowie S1-C | Keyboard: Ducky One 3 TKL (Cherry MX-Speed-Silver)Beyerdynamic MMX 300 (2nd Gen) | Acer XV272U | OS: Windows 11 |

Link to comment
Share on other sites

Link to post
Share on other sites

Good, I'm fully qualified. Now if only I knew what the hell I should be even looking for...

The ability to google properly is a skill of its own. 

Link to comment
Share on other sites

Link to post
Share on other sites

Gotta love dem white hat hackers.

Mobo: Z97 MSI Gaming 7 / CPU: i5-4690k@4.5GHz 1.23v / GPU: EVGA GTX 1070 / RAM: 8GB DDR3 1600MHz@CL9 1.5v / PSU: Corsair CX500M / Case: NZXT 410 / Monitor: 1080p IPS Acer R240HY bidx

Link to comment
Share on other sites

Link to post
Share on other sites

I thought they already paid people for reporting security issues. Did that program exclude IE before?

Link to comment
Share on other sites

Link to post
Share on other sites

Barnacules get to work

"work". Right hahahahah

MacBook Pro 15' 2018 (Pretty much the only system I use)

Link to comment
Share on other sites

Link to post
Share on other sites

Security issue found: it borrows some code from IE. Where's my 15 grand?

Rich Purnell Is A Steely-Eyed Missile Man

Link to comment
Share on other sites

Link to post
Share on other sites

It's actually pretty reasonable rates considering the hundreds of thousands if not millions of dollars they lose every time a massive exploit is found.

i7 6700K - ASUS Maximus VIII Ranger - Corsair H110i GT CPU Cooler - EVGA GTX 980 Ti ACX2.0+ SC+ - 16GB Corsair Vengeance LPX 3000MHz - Samsung 850 EVO 500GB - AX760i - Corsair 450D - XB270HU G-Sync Monitor

i7 3770K - H110 Corsair CPU Cooler - ASUS P8Z77 V-PRO - GTX 980 Reference - 16GB HyperX Beast 1600MHz - Intel 240GB SSD - HX750i - Corsair 750D - XB270HU G-Sync Monitor
Link to comment
Share on other sites

Link to post
Share on other sites

I thought they already paid people for reporting security issues. Did that program exclude IE before?

I guess the bounties are bigger or they want to publicise it more

CPU: AMD Ryzen 7 3700X - CPU Cooler: Deepcool Castle 240EX - Motherboard: MSI B450 GAMING PRO CARBON AC

RAM: 2 x 8GB Corsair Vengeance Pro RBG 3200MHz - GPU: MSI RTX 3080 GAMING X TRIO

 

Link to comment
Share on other sites

Link to post
Share on other sites

$15,000.. that's so much audio-equipment and steak.  Well played Microsoft.  Well played.

Link to comment
Share on other sites

Link to post
Share on other sites

lol only 15k for remote code execution? do you even know how much a 0day goes for?.....

------------------------------------------------------I HAZ SHINY----------------------------------------------------------


Link to comment
Share on other sites

Link to post
Share on other sites

tumblr_ljhx7g621D1qcfyhd.png

"My game vs my brains, who gets more fatal errors?" ~ Camper125Lv, GMC Jam #15

Link to comment
Share on other sites

Link to post
Share on other sites

What I'd like to know is; how much money do we get if we don't find any security flaws?   :P Gotta be worth something, right?

Link to comment
Share on other sites

Link to post
Share on other sites

lol only 15k for remote code execution? do you even know how much a 0day goes for?.....

 

This. You have to be really honest or really afraid of prosecution to turn over a zero day RCE for $15K...

 

I'd probably pay $100K for a significant RCE vulnerability if I were them.

Turnip OC'd to 3Hz on air

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×