Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's a pity the article only mentions client-side exploits, it would have been interesting to see what is paid for server-side zero-days, especially linux/LAMP related...


Consider the possibility that governments can create their own exploits. If they have a large quantity of server side bugs the marginal utility of one more is effectively 0. It is safe to assume that they have existing capabilities in that area. Just mentioning a LAMP stack means SQLi as the most likely vector. No point in paying for someone to run sqlmap for you... ;)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: