Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- We are ready to acquire information about the unique 0day vulnerabilities and 0day exploits.
- RULES OF REPRESENTATION
- We constantly buy 0day and Nday vulnerabilities and exploits. We do not pay for hypothetical vulnerabilities.
- Please provide a brief technical description of the vulnerabilities and exploits on our form to our
- e-mail: vulnsisrock@tuta.io
- Your vulnerability will be analyzed and evaluated by us within 48 hours. Remuneration can be paid in cash,
- bank transfers or anonymous transfers using crypto conversions. We are considering an additional premium
- for exclusive conditions for us in the form of additional quarterly payments to researchers before disclosure
- of the vulnerability.
- Prices 0days can be higher than indicated in the table all depends on the quality of the exploits, we are
- ready to negotiate the price on a bilateral basis.
- We also provide the service ESCROW service when both parties can not agree and do not trust each other.
- Agents and brokers are welcome, we pay high commissions for help in acquiring 0day vulnerabilities.
- We reserve the right to refuse to purchase your materials.
- PURCHASE TERMS
- 1. You discover a vulnerability and create a functional prototype of exploits (PoC)
- 2. You write a short technical description of the vulnerability found and send it to us.
- 3. Within 48 hours we will answer you in writing our interest and prevernuyu cost we are willing to pay you.
- 4. If you agree, you provide us with full technical information, including a functional prototype.
- 5. We check the exploit you provided and pay you a reward according to the method you selected within 24 hours.
- If you have any counter proposals regarding the acquisition process, you can always contact us. We can organize
- a personal meeting with you in practical any country in the world to personally discuss all the issues personally.
- PRICE TABLE
- +------------------------------------------+ +-------------------------+
- | INTEGRATED CIRCUITS | | SCADA PLC |
- |------------------------------------------| |-------------------------|
- |Smart Cards | $100,000+ | | Siemens | $30,000+ |
- |Cellular SoC (MTK, Qualcomm) | $50,000+ | | Honeywell | $20,000+ |
- |CPLD/FPGA | $50,000+ | | Mitsubishi | $15,000+ |
- |Microcontrollers | $30,000+ | | Omron | $10,000+ |
- +------------------------------------------+ | ABB | $10,000+ |
- | Schneider | $10,000+ |
- | Other | $5,000+ |
- +---------------------+ +-------------------------+
- | ATM |
- |---------------------| +------------------------------------------------------+
- | Wincor | $25,000+ | | NETWORK DEVICES |
- | NCR | $25,000+ | |------------------------------------------------------|
- | Diebold | $15,000+ | | Juniper | $50,000+ |
- | Other | $15,000+ | | Cisco | $50,000+ |
- +---------------------+ | Sonicwall | $50,000+ |
- | F5 | $50,000+ |
- +---------------------------+ | SIP Avaya, Asterisk, Polycom and others | $50,000+ |
- | SMART TV | | Riverbed | $50,000+ |
- |---------------------------| | HP | $10,000+ |
- | Samsung | $10,000+ | | Huawei | $10,000+ |
- | Sony | $10,000+ | | Asus | $5,000+ |
- | Panasonic | $10,000+ | | ZyXEL | $5,000+ |
- | LG | $5,000+ | | Netgear | $5,000+ |
- | Home Appliance | $5,000+ | | D-Link | $5,000+ |
- +---------------------------+ | Other | $1,000+ |
- +------------------------------------------------------+
- +-------------------------------------+ +---------------------------------+
- | IPMI | | GAMING CONSOLES |
- |-------------------------------------| |---------------------------------|
- | Sun SSP | $100,000+ | | Xbox ONE X (RCE) | $75,000+ |
- | Dell DRAC | $100,000+ | | Playstation 4 (RCE) | $75,000+ |
- | HP iLO | $100,000+ | | Nintendo (RCE) | $50,000+ |
- | Supermicro IPMI | $100,000+ | +---------------------------------+
- | Cisco CIMC | $50,000+ |
- | VNC, Teamviewer, Radmin | $50,000+ |
- | Other | $20,000+ |
- +-------------------------------------+
- +---------------------------+
- | PERIPHERAL DEVICES |
- +---------------------------------------------------+ |---------------------------|
- | MOBILE DEVICES | | Scanners (RCE | $30,000+ |
- |---------------------------------------------------+ | Printers (RCE) | $30,000+ |
- | Apple iOS (LCE,RJB) | $2,500,000+ | | CCTV (RCE) | $10,000+ |
- | Android (RJB) | $2,500,000+ | +---------------------------+
- | SMS/MMS (RCE+LPE) (Any Mobile OS) | $2,500,000+ |
- | WiFi (RCE+LPE) (Any Mobile OS) | $100,000+ |
- | Bluetooth (RCE+LPE) (Any Mobile OS) | $50,000+ |
- | Sandbox Escape (Any Mobile OS) | $30,000+ |
- | WatchOS (LCE,RJB) | $100,000+ |
- +---------------------------------------------------+
- +-----------------------------------------+ +------------------------------------+
- | OPERATING SYSTEMS | | DATABASE SOFTWARE |
- |-----------------------------------------| |------------------------------------|
- | Windows Server (RCE, SE) | $500,000+ | | MS SQL Server (RCE) | $200,000+ |
- | Windows 7/8.1/10 (LPE, SE) | $150,000+ | | Oracale Database (RCE) | $200,000+ |
- | MacOS (LPE, SE) | $50,000+ | | MongoDB (RCE) | $150,000+ |
- | Linux Desktop/Server (LPE) | $50,000+ | | MySQL (RCE) | $150,000+ |
- | Virtual Machine Escape | $150,000+ | | MS Access (RCE) | $20,000+ |
- +-----------------------------------------+ +------------------------------------+
- +-------------------------------------------------+
- | PRODUCTIVITY APPS | +----------------------------------------+
- |-------------------------------------------------+ | MESSENGERS |
- | MS Office Word, Excel, PP (RCE) | $250,000+ | +----------------------------------------|
- | Adobe PDF Reader all (RCE, SE) | $250,000+ | | Telegram (RCE) | $1,000,000+ |
- | Adobe Flash Player (RCE, SE) | $150,000+ | | WhatsApp (RCE) | $1,000,000+ |
- | Microsoft Silverlight(RCE, SE) | $100,000+ | | Facebook Messenger (RCE) | $250,000+ |
- | Antivirus (RCE, LPE) | $30,000+ | | WeChat (RCE) | $250,000+ |
- +-------------------------------------------------+ | Viber (RCE) | $150,000+ |
- | Imo (RCE) | $150,000+ |
- | Line (RCE) | $150,000+ |
- +----------------------------------------+
- +---------------------------------------+ +--------------------------------------------+
- | WEB SERVERS | | WEB BROWSERS |
- |---------------------------------------| |--------------------------------------------|
- | Microsoft IIS (RCE) | $250,000+ | | Google Chrome all OS (RCE, SE) | $300,000+ |
- | MS Exchange Server (RCE) | $300,000+ | | Microsoft Edge (RCE, SE) | $300,000+ |
- | Nginx (RCE) | $300,000+ | | TOR Browser (RCE, SE) | $300,000+ |
- | Appache Server (RCE) | $300,000+ | | Apple Safari OS X (RCE, SE) | $250,000+ |
- | Open SSL (RCE) | $250,000+ | | Mozilla Firefox (RCE, SE) | $150,000+ |
- | Lotus Domino (RCE) | $100,000+ | +--------------------------------------------+
- | JBoss (RCE) | $100,000+ |
- | Appache Tomcat (RCE) | $50,000+ |
- +---------------------------------------+
- +----------------------------------+
- +----------------------------------------------+ | BUGTRACKERS |
- | EMC | |----------------------------------|
- |----------------------------------------------| | Redmine | $30,000+ |
- | Microsoft SharePoint | $250,000+ | | Atlassian JIRA | $30,000+ |
- | IBM Fil-eNet | $150,000+ | | Bugzilla | $10,000+ |
- | Oracle WebCenter | $150,000+ | | Jenkins | $10,000+ |
- | OpenText Content Suite Platform | $50,000+ | | Atlassian Confluence | $10,000+ |
- +----------------------------------------------+ +----------------------------------+
- +----------------------------+ +-----------------------------+
- | FTP | | CMS |
- |----------------------------| |-----------------------------|
- | Filezilla (RCE) | $30,000+ | | Wordpress (RCE) | $100,000+ |
- | Titan (RCE) | $20,000+ | | 1C Bitrix (RCE) | $100,000+ |
- | Serv-U (RCE) | $20,000+ | | Joomla (RCE) | $80,000+ |
- | net2ftp (RCE) | $20,000+ | | Wix (RCE) | $25,000+ |
- +----------------------------+ | Drupal (RCE) | $25,000+ |
- +-----------------------------+
- +--------------------------------------+
- | FORUMS |
- |--------------------------------------| +----------------------------------------------+
- | IP.Board (RCE) | $50,000+ | | PLM and EPR |
- | VBulletin (RCE) | $50,000+ | |----------------------------------------------|
- | Lithium communities (RCE) | $50,000+ | | SAP | $100,000+ |
- | Mybb (RCE) | $25,000+ | | Siemens Teamcenter | $100,000+ |
- | PHPbb (RCE) | $25,000+ | | Oracle ERP | $100,000+ |
- | IP.Suite (RCE) | $25,000+ | | Oracle Agile PLM | $100,000+ |
- | XenForo | $20,000+ | | SPTC Windchill PLM | $50,000+ |
- | Woltlab BB (RCE) | $20,000+ | | MentorGraphics HyperLynx SI PLM | $50,000+ |
- +--------------------------------------+ | Enovia PLM | $30,000+ |
- +----------------------------------------------+
- +------------------------------------------+
- | MAIL SERVERS | +-------------------------------+
- |------------------------------------------| | HOSTING PANELS |
- | Microsoft Outlook OWA (RCE) | $200,000+ | |-------------------------------|
- | Sendmail (RCE) | $120,000+ | | cPanel (RCE) | $75,000+ |
- | IBM Lotus Domino (RCE) | $100,000+ | | Plesk (RCE) | $75,000+ |
- | Horde (RCE) | $50,000+ | | Direct Admin (RCE) | $25,000+ |
- | Roundcube (RCE) | $50,000+ | | Other (RCE) | $10,000+ |
- | Squirellmail (RCE) | $50,000+ | +-------------------------------+
- | Other mail servers (RCE) | $25,000+ |
- +------------------------------------------+
- LPE - Local Privilege Escalation
- RCE - Remote Code Execution
- SE - Sandbox Escape
- RJB - Remote Jailbreak
- LCE - Local Code Execution (physical access to device)
- In addition to vulnerabilities, we are interested in obtaining various research results, such as:
- - Deanonimization of TOR network resources
- - Bypassing ASLR, DEP, UAC and other security mechanisms
- - Attack vectors for remote code execution on devices via GSM, Bluetooth and WiFi
- - Vulnerabilities on mobile chipsets
- - Innovative detour of antiviruses
- - Other research results and technical information.
- EXPLOIT TECHNICAL INFORMATION
- All questions should have the most detailed answers from this depends on
- what price we will offer you for your 0day exploit.
- 1. Item name : _____________________________________________________________________
- 2. Asking Price and availability of exclusive acquisition : ________________________
- 3. Affected OS: ________________________
- 4. Vulnerable Target application versions and reliability. If 32 bit only, is 64 bit vulnerable?
- List complete point release range. ________________________________________________
- 5. Tested, functional against target application versions, list complete point release range.
- Explain ________________________________________________
- 6. Does this exploit affect the current target version?
- [ ] Yes
- [ ] No
- 7. Privilege Level Gained
- [ ] As logged in user (Select Integrity level below for Windows)
- [ ] Web Browser's default (IE - Low, Others - Med)
- [ ] Low
- [ ] Medium
- [ ] High
- [ ] Root, Admin or System
- [ ] Ring 0/Kernel
- [ ] Other
- 8. Minimum Privilege Level Required For Successful PE
- [ ] As logged in user (Select Integrity level below for Windows)
- [ ] Low
- [ ] Medium
- [ ] High
- [ ] N/A
- [ ] Other ________________________
- 9. Exploit Type (select all that apply)
- [ ] Remote code execution
- [ ] Privilege escalation
- [ ] Font based
- [ ] Sandbox escape
- [ ] Information disclosure (peek)
- [ ] Code signing bypass
- [ ] Persistency
- [ ] Other ________________________
- 10. Delivery Method
- [ ] Via web page
- [ ] Via file
- [ ] Via network protocol
- [ ] Local privilege escalation
- [ ] Other (please specify) ________________________
- 11. Bug Class
- [ ] memory corruption
- [ ] design/logic flaw (auth-bypass / update issues)
- [ ] input validation flaw (XSS/XSRF/SQLi/command injection, etc.)
- [ ] misconfiguration
- [ ] information disclosure
- [ ] cryptographic bug
- [ ] denial of service
- 12. Number of bugs exploited in the item: ________________________
- 13. Exploitation Parameters
- [ ] Bypasses ASLR
- [ ] Bypasses DEP / W ^ X
- [ ] Bypasses Application Sandbox
- [ ] Bypasses SMEP/PXN
- [ ] Bypasses EMET Version 5.52±
- [ ] Bypasses CFG (Win 8.1)
- [ ] N/A
- 14. Is ROP employed?
- [ ] No
- [ ] Yes (but without fixed addresses)
- - Number of chains included?
- ________________________
- - Is the ROP set complete?
- ________________________
- - What module does ROP occur from?
- ________________________
- 15. Does this item alert the target user?
- Explain ______________________________________________
- 16. How long does exploitation take, in seconds?
- 17. Does this item require any specific user interactions?
- 18. Any associated caveats or environmental factors? For example - does the exploit determine
- remote OS/App versioning,and is that required? Any browser injection method requirements?
- For files, what is the access mode required for success?
- 19. Does it require additional work to be compatible with arbitrary payloads?
- [ ] Yes
- [ ] No
- 20. Is this a finished item you have in your possession that is ready for delivery immediately?
- [ ] Yes
- [ ] No
- [ ] 1-5 days
- [ ] 6-10 days
- [ ] More: _______________________________
- 21. Impact on framework (crashes, etc.) ____________________________________________________
- 22. Success rate (or number of necessary attempts) _________________________________________
- 23. Does this item support continuation of execution?
- 24. Description. Detail a list of deliverables including documentation.
- 25. Testing Instructions : _________________________________________________________________
- 26. Comments and other notes; unusual artifacts, other limitations, mitigations or other
- pieces of information : ________________________________________________________________
Add Comment
Please, Sign In to add comment