Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×
Crime Bitcoin Security

New Dark Web Market Is Selling Zero-Day Exploits 30

Sparrowvsrevolution writes Over the last month, a marketplace calling itself TheRealDeal Market has emerged on the dark web, with a focus on sales of hackers' zero-day attack methods. Like the Silk Road and its online black market successors like Agora and the recently defunct Evolution, TheRealDeal runs as a Tor hidden service and uses bitcoin to hide the identities of its buyers, sellers, and administrators. But while some other sites have sold only basic, low-level hacking tools and stolen financial details, TheRealDeal's creators say they're looking to broker premium hacker data like zero-days, source code, and hacking services, often offered on an exclusive, one-time sale basis.

Currently an iCloud exploit is being offered for sale on the site with a price tag of $17,000 in bitcoin, claiming to be a new method of hacking Apple iCloud accounts. "Any account can be accessed with a malicious request from a proxy account," reads the description. "Please arrange a demonstration using my service listing to hack an account of your choice." Others include a technique to hack WordPress' multisite configuration, an exploit against Android's Webview stock browser, and an Internet Explorer attack that claims to work on Windows XP, Windows Vista and Windows 7, available for around $8,000 in bitcoin. None of these zero days have yet been proven to be real, but an escrow system on the site using bitcoin's multisignature transaction feature is designed to prevent scammers from selling fake exploits.
This discussion has been archived. No new comments can be posted.

New Dark Web Market Is Selling Zero-Day Exploits

Comments Filter:
  • This sounds like a honeypot to me..

    • Re:first (Score:4, Insightful)

      by monkeyzoo ( 3985097 ) on Monday April 20, 2015 @12:43PM (#49511791)

      Perhaps the vendors themselves should buy the exploits. Perhaps, it's not that different than a bounty program except for the fact that market pricing would determine the value of a vulnerability (and the lack of nobility in the mercernary nature of the process).

    • by Anonymous Coward

      Really! 'Dark Web'... Hollywood invades the Internet! It's not like I'm sexist or anything, but how come guys have to keep proving how dumb they are? Broken Beer Bottles here too...

    • This sounds like a honeypot to me..

      Especially when selling 0-days isn't actually illegal in most circumstances, only rather shady. Researchers do deals all the time. Total anonymity on one or both sides doesn't really help anyone. Hell, it's so commonplace they have discussed it on NPR: http://www.npr.org/blogs/money... [npr.org]

      If anything this is just a new way to scam people out of money or to ferret out security researchers for further recruitment/waterboarding by the CIA.

  • First thoughts... (Score:2, Interesting)

    by Anonymous Coward

    At first I realized even on the darknet, and for exploits, Apple commands a price premium. Hopefully the exploit is well polished and deserves this premium. Second, the site uses a multiple signature escrow system to assure an exploit is real. The presumption being the site is real and is not itself a means to pirate Bitcoin by them being put in escrow.

    • Second, the site uses a multiple signature escrow system to assure an exploit is real. The presumption being the site is real and is not itself a means to pirate Bitcoin by them being put in escrow.

      Any idea how that works? The only way I know of to produce partial keys has one person entirely in charge, which wouldn't work for an untrusted escrow service.

      And unlike most Dark Web markets, it allows only so-called multisignature transactions. That means the bitcoins are held at an address jointly controlled by the buyer, the seller, and the market’s admins. For the money to be moved to the seller’s account, two out of three of those parties must sign off on the deal, giving the administrators the tie-breaking vote to resolve disputes.

      • Any idea how that works? The only way I know of to produce partial keys has one person entirely in charge, which wouldn't work for an untrusted escrow service.

        Bitcoin allows for escrow and arbitration where you can select any arbitrator both parties trust and agree to and thus eliminates counterparty risk. The keys are split with either multi-sig or shamir's secret sharing.. here is one example amongst many:

        https://www.bitrated.com/ [bitrated.com]

  • you can celebrate any day all day.

What is research but a blind date with knowledge? -- Will Harvey

Working...