ChefGordonR

Zero Security Cooperation

Nov 6th, 2020 (edited)
1,744
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 8.86 KB | None | 0 0
  1.  
  2. Zero Security
  3. We are ready to acquire information about the unique 0day vulnerabilities and 0day exploits.
  4.  
  5. RULES OF REPRESENTATION
  6. We constantly buy 0day and Nday vulnerabilities and exploits. We do not pay for hypothetical vulnerabilities.
  7. Please provide a brief technical description of the vulnerabilities and exploits on our form to our
  8. Your vulnerability will be analyzed and evaluated by us within 48 hours. Remuneration can be paid in cash,
  9. bank transfers or anonymous transfers using crypto conversions. We are considering an additional premium
  10. for exclusive conditions for us in the form of additional quarterly payments to researchers before disclosure
  11. of the vulnerability.
  12. Prices 0days can be higher than indicated in the table all depends on the quality of the exploits, we are
  13. ready to negotiate the price on a bilateral basis.
  14.  
  15. We also provide the service ESCROW service when both parties can not agree and do not trust each other.
  16. Agents and brokers are welcome, we pay high commissions for help in acquiring 0day vulnerabilities.
  17. We reserve the right to refuse to purchase your materials.
  18.  
  19. If you have any counter proposals regarding the acquisition process, you can always contact us. We can organize
  20. a personal meeting with you in practical any country in the world to personally discuss all the issues personally.
  21.  
  22. PRICING
  23. The price will depend on the technical information submitted. Once submitted we will respond with an offer which may be countered or accepted.
  24.  
  25. In addition to vulnerabilities, we are interested in obtaining various research results, such as:
  26. - Deanonimization of TOR network resources
  27. - Bypassing ASLR, DEP, UAC and other security mechanisms
  28. - Attack vectors for remote code execution on devices via GSM, Bluetooth and WiFi
  29. - Vulnerabilities on mobile chipsets
  30. - Innovative detour of antiviruses
  31. - Other research results and technical information.
  32.  
  33.  
  34.  
  35. ZERO SECURITY EXPLOIT TECHNICAL INFORMATION
  36.  
  37. All questions should have the most detailed answers from this depends on what price we will offer you for your 0day exploit.
  38.  
  39. 1. Item name :________________________________________________
  40. 2. Vendor Homepage:________________________________________________
  41. 3. Vulnerable Software:________________________________________________
  42. 4. Asking Price and availability of exclusive acquisition : ________________________
  43. 5. Affected OS: ________________________
  44. 6. Vulnerable Target application versions and reliability. If 32 bit only, is 64 bit vulnerable?
  45. List complete point release range. ________________________________________________
  46. 7. Tested, functional against target application versions, list complete point release range.
  47. Explain ________________________________________________
  48. 8. Does this exploit affect the current target version?
  49. [ ] Yes
  50. [ ] No
  51. 9. Targets can be found with google dork/shodan/censys?
  52. [ ] Yes
  53. [ ] No
  54. 10. Privilege Level Gained
  55. [ ] As logged in user (Select Integrity level below for Windows)
  56. [ ] Web Browser's default (IE - Low, Others - Med)
  57. [ ] Low
  58. [ ] Medium
  59. [ ] High
  60. [ ] Root, Admin or System
  61. [ ] Ring 0/Kernel
  62. [ ] Other
  63. 11. Minimum Privilege Level Required For Successful PE
  64. [ ] As logged in user (Select Integrity level below for Windows)
  65. [ ] Low
  66. [ ] Medium
  67. [ ] High
  68. [ ] N/A
  69. [ ] Other ________________________
  70. 12. Exploit Type (select all that apply)
  71. [ ] Remote code execution
  72. [ ] Privilege escalation
  73. [ ] Font based
  74. [ ] Sandbox escape
  75. [ ] Information disclosure (peek)
  76. [ ] Code signing bypass
  77. [ ] Persistency
  78. [ ] Other ________________________
  79. 13. Delivery Method
  80. [ ] Via web page
  81. [ ] Via file
  82. [ ] Via network protocol
  83. [ ] Local privilege escalation
  84. [ ] Other (please specify) ________________________
  85. 14. Bug Class
  86. [ ] memory corruption
  87. [ ] design/logic flaw (auth-bypass / update issues)
  88. [ ] input validation flaw (XSS/XSRF/SQLi/command injection, etc.)
  89. [ ] misconfiguration
  90. [ ] information disclosure
  91. [ ] cryptographic bug
  92. [ ] denial of service
  93. 15. Number of bugs exploited in the item: ________________________
  94. 16. Exploitation Parameters
  95. [ ] Bypasses ASLR
  96. [ ] Bypasses DEP / W ^ X
  97. [ ] Bypasses Application Sandbox
  98. [ ] Bypasses SMEP/PXN
  99. [ ] Bypasses EMET Version 5.52±
  100. [ ] Bypasses CFG (Win 8.1)
  101. [ ] N/A
  102. 17. Is ROP employed?
  103. [ ] No
  104. [ ] Yes (but without fixed addresses)
  105. - Number of chains included?
  106. ________________________
  107. - Is the ROP set complete?
  108. ________________________
  109. - What module does ROP occur from?
  110. ________________________
  111. 18. Does this item alert the target user?
  112. Explain ______________________________________________
  113. 19. How long does exploitation take, in seconds?
  114. 20. Does this item require any specific user interactions?
  115. 21. Any associated caveats or environmental factors? For example - does the exploit determine
  116. remote OS/App versioning,and is that required? Any browser injection method requirements?
  117. For files, what is the access mode required for success?
  118. 22. Does it require additional work to be compatible with arbitrary payloads?
  119. [ ] Yes
  120. [ ] No
  121. 23. Is this a finished item you have in your possession that is ready for delivery immediately?
  122. [ ] Yes
  123. [ ] No
  124. [ ] 1-5 days
  125. [ ] 6-10 days
  126. [ ] More: _______________________________
  127. 24. Does this exploit weaponized ?
  128. [ ] Yes
  129. [ ] No
  130. 25. Impact on framework (crashes, etc.) ____________________________________________________
  131. 26. Success rate (or number of necessary attempts) _________________________________________
  132. 27. Does this item support continuation of execution?
  133. 28. Description. Detail a list of deliverables including documentation.
  134. 29. Testing Instructions : _________________________________________________________________
  135. 30. Comments and other notes; unusual artifacts, other limitations, mitigations or other
  136. pieces of information : ________________________________________________________________
  137.  
  138.  
  139. -----BEGIN PGP PUBLIC KEY BLOCK-----
  140. mQGNBF+kNhkBDAC7LmMmoCI6oOgRMRacr+dFW6bBOAPYTDqalEbtf2LS3aicbqlE
  141. VvaeZJJNwZA5H7kGO7LrmDNXD59y3wxhtHgciK0B/sIh6+qSDd2F4SDMXut8nYPN
  142. WFnRlA4wXSbig9HIcXVlnyDSADpTdIlmalMvf0fd0Sx10vAWUuqjh2eM3bZraCwi
  143. 9IPy8alGDuyMD5+HDX5YWgln6m4HOHg2muVlSJ+6ztWOX19DXywpwOHQFld+LH6l
  144. gLGd3WJ/PrVV7lmBLmSFpqAJVtmSvxCTy+ItvorLY5KrEwNn2Tsomr7WboVLpoDC
  145. jlqnd1xr2lR4gCYNO1M6ssH7cbKoETxLm06oHhmRmm0MwOriFKdbaYP5wKU0YrJG
  146. PAZB647hwofAE786zIwR0Zdc0lWBk9XtVK2YnTswJW1+PIPmsO8sjGxhIyZ4dueI
  147. Jp5giu2oJp1xSi8Yh/mPKBrNgcuGqaJ1HLmeDiA84dn9ztApE41cy7TI8ZJhsQnj
  148. r18HKiYxAdPIPIkAEQEAAbQkSmFtZXMgR3JhbmRvZmYgPEpHcmFuZG9mZkAwLXNl
  149. Yy5uZXQ+iQHUBBMBCAA+FiEEduOVe3cX2HGW8u6LbTdnsBNScw0FAl+kNhkCGwMF
  150. CQPCUmcFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQbTdnsBNScw2trQv/T422
  151. ooaoDq8aS06oSJ+lLIoiCUhknQ1P6woixFCs8ganIwyqVIngaf9ypR1JnVwEMAsB
  152. gDpskMLIUEsXt0i/RRZH0ytF2KOaI/3430mnmum55iV6fT42L+psvn6D+By0zkkF
  153. 5DXTCy1pY4LkQdeaJAQ7C6nC7EfsqTeZizItTyRVI3IhbQk0DTAo1A3zPWMpXtYz
  154. 8CIviOgIHasbR8V52vUPcGcog7uOWnq25OxQn0xVJSGJz8lRhP6+YgbmG+AWFGEE
  155. DC0G4xINx4LlR2eVNS/lDfD5hdK+LzIAhuRdkqjcFKgzygBMGI4UY5Fd/9Ru2g+S
  156. gnr3j3T0sGyUmTXaSZV2VVBPBqOQNE4Av5ZAISRMqkO8yxvJzyNNdsV8+Qz9OWpY
  157. F7ZlFPyutvQaQx+Sexf+/JLyPie86qg4mlQo2AEBlxdzMtpS+mKcaRaukp94P8zh
  158. inF/7RQRaJOLcOibXba23Kooqn23EyEMZUX3qgA6Q6gUTdKfJu87hHnmbFxLuQGN
  159. BF+kNhkBDADZBC1lxh/9KkjNsmmOcdvrH7s9nxrrZx8qJzec1KA+gkX3ZUGlL+0E
  160. sKl6uVMioLpNjQcvgAmijBREU4LBWd12gHP1vsVxcpMH3iE4I2PJ87nQoDvEC+f1
  161. 3nAm9aEWtNlIVuO37AZku/gnfmFke/jWR5qZlcMukoCQR2oXdDM0SFoUN05ItxyW
  162. kh08H9WpqRSZRc/DBbAdvrOtXgHldk4cJrkedPLc5m8HYrWMfuaFvqAcO3mG2Xu2
  163. viEXrIo847lg6xgKCJIYn2LiG3dkrrPWpWquWZbRzoswQ68A/0esn9n2LcbGhG5X
  164. kc57x35vtx+OhWDv+Fy2fdy6pQXWYRFLwdj36w0FsdoxC5nu+SjI83rU28d0kLHs
  165. 4ii4cpdikp1DR96wow2XkJ7s7bUjnfFe72ackJDeLcoXvKrr5246FGfmGg9cDVzv
  166. KKfXCX52JjJ1rI8YFwL1lRgJW1adLB5yOlQIWi//QUNV+6kxpFwIU556H+qT7VbH
  167. eF/+79YdZIsAEQEAAYkBvAQYAQgAJhYhBHbjlXt3F9hxlvLui203Z7ATUnMNBQJf
  168. pDYZAhsMBQkDwlJnAAoJEG03Z7ATUnMNn44L/A51DXNDE0Jlu1rnyu0kP6R83M8g
  169. SJc2KHJaafy36Q3tISJzRWQ0vzUo1IbmbW7m0jU+rJ5PoRJ1gaS/r2L5eDJ66f4I
  170. oWXIkH4sKDTgLdQOhSIlJNe5w6J7bCUNbtDsowUvBFYdocFsMCollguIjlqITuRD
  171. 2iocHd7Qwg4YT6Y6wk30XNtl+ypr0u+fri/nxGRG/0dBr6eZfBIk1vdjWGasMOxL
  172. eSclr4I/loxh3qBYHlueEzeH3TWM6DQ83rj8CfRD6Bs8+x1JWt0XjtXDYC1DzMja
  173. KTzgqgIuJhKNYRciWHdQIYdpK8qnAkBsgqYR8khZfv1f8mKB/NJZbSv8O7KMRj+9
  174. uxrhxDWXSzJm+iSpGIz+mD6adWsN7hbVLXblrEDb2B92RKVwTRz3IE+EhTOWAiMM
  175. fx4M95b1drcrbavOGqhI5Wbm7IAqi4O8z7DFFdYqjZNRkGxsJCLLu3+mlHB/HXYL
  176. gZLGm8p2SKkOiv5fvsylyb9AEaYBczL35T6eDA==
  177. =losg
  178. -----END PGP PUBLIC KEY BLOCK-----
Add Comment
Please, Sign In to add comment