Overblog Alle Blogs Top-Blogs Technologie & Wissenschaft
Edit post Folge diesem Blog Administration + Create my blog
MENU
Werbung

Kim Dotcom launches Mega vulnerability reward instruct, offering up to $13,500 apiece bug

Veröffentlicht am 3. Februar 2013

 

Kim Dotcom launches Mega vulnerability reward instruct, offering up to $13,500 apiece bug
Article by http://www.Laptop-battery.Sg : Kim Dotcom has officially launched his Mega vulnerability reward instruct with the aim of was announced carry on week. To the same degree we reported earlier, the come to nothing of Mega, the newly launched sort luggage compartment service, is challenging anybody to loud noise a previously unknown security-relevant bug or else design flaw. The inducement? He’s offering up to €10,000 apiece bug (approx. US$13,580), “depending on its complexity and waves budding.”
 
The #Mega crypto & security REWARD instruct is live. Earn up to 10,000 EURO apiece vulnerability. Mega.Co.Nz/#blog_6
 
— Kim Dotcom (@KimDotcom) February 2, 2013
 
With this reward instruct, Kim Dotcom seeks to added convalesce his spanking service’s security approach. He says with the aim of rectify in imitation of the launch, Mega’s security develop and implementation came “under intense crossfire” (especially from Ars Technica and Forbes) and has besides suffered several attacks. And it’s eager pro additional so it can discover to better defend itself from unauthorized intrusions and bolster its protection.
 
It’s principal to memo with the aim of participants may well receive up to €10,000 so it’s grave to understand I beg your pardon? Bugs qualify. According to the company:
 
Remote code execution on every of our servers (including SQL injection)
Remote code execution on every client browser (e.G., through XSS)
Every gush with the aim of breaks our cryptographic security develop, allowing unauthorized remote access to or else manipulation of keys or else data
Every gush with the aim of bypasses access control, allowing unauthorized overwriting/destruction of keys or else user data
Every gush with the aim of jeopardizes an account’s data indoors situation the associated e-mail dispatch is compromised
Solitary folks who are dogged to take place the “first finder of the bug” are eligible pro the prize, and folks reported by third-parties are not typically considered pro the reward.
 
To the same degree part of this instruct, Mega has presented three special scenarios pro hackers to try and solve:
 
Compromised static CDN node (*.Static.Mega.Co.Nz): Let’s feign with the aim of you take part in compromised single of our static content servers and are able to manipulate the library (including all JavaScript code) served from it. Can you influence with the aim of achievement to compromise our security? Disclaimer: Influencing user measures through modified image library, while indeed a budding vulnerability indoors this context, is barred!
Compromised user luggage compartment node (*.Userstorage.Mega.Co.Nz): Let’s feign with the aim of you take part in gained access to single of our luggage compartment nodes and are able to manipulate it without restraint. You know with the aim of your victim is more or less to download a regard sort residing on with the aim of node, but you don’t take part in its scale. Can you manipulate its content so with the aim of it still downloads devoid of mistake?
Compromised underlying infrastructure (*.Api.Mega.Co.Nz): This is the nearly everyone extreme scenario. Let’s feign with the aim of you take part in compromised our operational core, the API servers. Can you trick API clients into granting usable keys pro library indoors accounts with the aim of accomplish not take part in every outgoing shares indoors them?
Dotcom is besides tossing indoors an extra option to reap the reward: The brute-force challenge. With this instruct, anybody who can remit him the scale with the aim of decrypts a particular sort along with the password encoded indoors a signup confirmation link may well take place eligible to receive the limit reward.
 
The company says with the aim of anybody who finds a bug can submit it to bugs@mega.Co.Nz.
 
The timing of Mega’s vulnerability reward instruct is attention-grabbing, especially indoors light of the cyberattacks made on the Washington stake, The spanking York time, and the fence in Street Journal. Additionally, the humankind found banned in our day with the aim of Twitter was besides a target of an attack with the aim of occurred this week.
 
Mega launched in a minute two weeks before and is storing not quite 50 million library. In imitation of in a minute single daylight online, it accepted a million registered users. On January 31, Dotcom announced his spanking initiative via Twitter:
 
#Mega‘s release source encryption remains unbroken! We’ll offer 10,000 EURO to anybody who can break it. Expect a blog stake in our day.
 
— Kim Dotcom (@KimDotcom) February 1, 2013
 
Dotcom has certainly kept back the situate occupied. Mega has in a minute recently blocked a third-party search engine, Mega-Search.Me, from accessing publicly to be had library shared by its users. It says it did so not solitary for the reason that the search engine used Mega’s branding devoid of its go-ahead, but besides with the aim of it didn’t take part in a Digital Millennium Copyright be in (DMCA) takedown guidelines or else registered agent.
 
Defensive the company and its users is an principal factor pro Dotcom, especially if it’s from the government. Whilst we asked him whether Mega would tag on the same future to the same degree his prior endeavor, Megaupload, he thought it would take place an entirely various place. With Mega, the situate is built purely indoors HTML5 and solitary ropes Chrome. Additionally, the situate doesn’t take advantage of every existing machinery. Dotcom says with the aim of the servers were built from the ground up with the aim of he believes yearn for prevent it from being exploited — for the reason that it’s his own machinery.
 
To the same degree a consequence of having one’s own custom machinery, a budding disadvantage is with the aim of extensive hard ought to take place ready indoors order to flush banned all vulnerabilities. Mega is straight away crowdsourcing to concoct really with the aim of it’s protected from every and all dangers.
Tags : Kim,mega,

 

Werbung
Kim Dotcom launches Mega vulnerability reward instruct, offering up to $13,500 apiece bug
Werbung
Kommentiere diesen Post
Werbung