Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Click for more information, or
Home Enterprise I.T. Cloud Computing Applications Hardware More Topics...
GET RECOGNIZED.
Let an ISACA® certification
elevate your career.

Register today and save
Network Security
DDoS Protection Powered By Verisign
Average Rating:
Rate this article:  
Security Researcher Scores $100K for Finding Windows Bugs

Security Researcher Scores $100K for Finding Windows Bugs
By Barry Levine

Share
Share on Facebook Share on Twitter Share on Linkedin Share on Google Plus

UK security researcher James Forshaw is close to making a living from besting Microsoft. In addition to the $100,000, he has also been the single biggest recipient of the IE 11 reward program, receiving $4,400 for four detected bugs and $5,000 for a security design problem. And Microsoft is not his only bug-payer. He has also received a substantial reward from HP.
 


$100,000. That's the bounty Microsoft has just paid to a security researcher who was able to find a class of bugs in Windows 8.1 Preview that could bypass system protections.

The researcher, James Forshaw of Context Information Security in the United Kingdom, has been rewarded through a program that was announced in January by Microsoft, under which the company pays third-party researchers for helping to uncover vulnerabilities in the company's products.

The $100,000 reward is not for each bug detected, but for finding classes of bugs that will allow Microsoft to set up defenses against a variety of attacks. But what did he find? Microsoft is understandably being coy on those details, except to say that the discovered approach could bypass system-level defenses, which could include, say, Data Execution Prevention, commonly used in modern operating systems to prevent the execution of code from non-executable memory.

$128,000 Paid Out

Forshaw is close to making a living from besting Microsoft. In addition to the $100,000, he has also been the single biggest recipient of the IE 11 reward program, receiving $4,400 for four detected bugs and $5,000 for a security design problem. And Microsoft is not his only bug-payer. He has also received a substantial reward from Hewlett-Packard for figuring out ways to take unauthorized control of Oracle's Java software.

In announcing the $100,000 bounty, Microsoft noted on its Bluehat Blog that one of its own engineers, Thomas Garnier, "had also found a variant of this class of attack technique." However, the company said that Forshaw's submission "was of such high quality and outlined some other variants such that we wanted to award him the full $100,000 bounty."

The technology giant said it was making high payouts for a new attack technique, instead of smaller payments for bugs, because the new technique allows the development of defenses against entire classes of malware.

So far, Microsoft said, it has paid out more than $128,000 in its new bounty programs. The programs were announced in June -- a Mitigation Bypass Bounty, a BlueHat Bonus for Defense, and an Internet Explorer 11 Preview Bug Bounty.

Five Others

The Mitigation Bypass offering pays up to $100,000 for "truly novel exploitation techniques" that bypass protections built into the latest OS version, Windows 8.1 Preview. The BlueHat Bonus has a reward of as much as $50,000 for "defensive ideas that accompany a qualifying Mitigation Bypass submission."

The IE 11 Bounty has a cap of $11,000 for revealing critical vulnerabilities in the Internet Explorer 11 Preview in Windows 8.1. Both Mitigation Bypass and BlueHat are ongoing, while the IE 11 Bounty only existed for the first 30 days of the browser's beta period, during June and July. IE 11 will be shipping on Oct. 18, when version 8.1 of the Windows operating system does.

Last week, Microsoft announced five others besides Forshaw who also received bounties under the program, in amounts ranging from $500 to $5,500. Two of the recipients work at Google.
 

Tell Us What You Think
Comment:

Name:



Salesforce.com is the market and technology leader in Software-as-a-Service. Its award-winning CRM solution helps 82,400 customers worldwide manage and share business information over the Internet. Experience CRM success. Click here for a FREE 30-day trial.


 Network Security
1.   Target Data Breach Cost: $148 Million
2.   Aruba Handles Black Hat with Aplomb
3.   Chinese Hackers Steal Patient Data
4.   FBI Cybersquad To Add Agents
5.   Apple Opens China iCloud Data Center


advertisement
Target Data Breach Cost: $148 Million
Better customer data protection needed.
Average Rating:
Aruba Handles Black Hat with Aplomb
Network firm sees 2,376 DoS attacks.
Average Rating:
FBI Cybersquad To Add Agents
Rewarded for recent security successes.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Cost of Target Data Breach: $148 Million Plus Loss of Trust
The now infamous Target data breach is still costing the company -- and its shareholders -- plenty. In fact, the retailing giant forecast the December 2013 incident cost shareholders $148 million.
 
Aruba Networks Handles Black Hat with Aplomb
It's not an easy job. Aruba Networks' task throughout the Black Hat USA conference in Las Vegas this month was to ensure thousands of attendees could connect without malicious attacks.
 
Chinese Hackers Nab Info on Millions of U.S. Patients
A group of Chinese hackers has stolen the personal information, including names and Social Security numbers, of about 4.5 million patients at hospitals operated by Community Health Systems.
 

Enterprise Hardware Spotlight
Three New Lenovo PCs Aimed at Business Users
Businesses everywhere want computing solutions that do more for less money, and Lenovo has unveiled three new desktop PCs that offer solid computing at a budget-minded price.
 
Aruba Networks Handles Black Hat with Aplomb
It's not an easy job. Aruba Networks' task throughout the Black Hat USA conference in Las Vegas this month was to ensure thousands of attendees could connect without malicious attacks.
 
Compression, Deduplication Come to Violin Concerto 2200
Violin Memory has announced that data deduplication and compression capabilities are now available on its Concerto 2200 solution. Typically, users will experience deduplication rates between 6:1 and 10:1.
 

Mobile Technology Spotlight
Apple Stock Soars Ahead of iPhone 6 Launch
The imminent release of the iPhone 6 -- and maybe even an iWatch -- has sent Apple's stock soaring to new heights. Considering what else the firm could have up its sleeve -- the stratosphere may be the limit.
 
HTC Debuts Windows Phone Version of One M8 Smartphone
HTC is bringing the Windows Phone mobile OS to its flagship One M8 device -- the first time any mainstream flagship smartphone has been offered with a choice of operating systems.
 
Verizon Earns Top Rating in Mobile Network Comparison
A new report says Verizon Wireless was the top-performing U.S. cellphone service provider in the first half of 2014, on a nationwide and state-by-state basis, as well as in metro areas.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud Computing | Applications | Hardware | Mobile Tech | Big Data | Communications
World Wide Web | Network Security | Data Storage | CRM Systems | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.