Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Zero Security
- We are ready to acquire information about the unique 0day vulnerabilities and 0day exploits.
- RULES OF REPRESENTATION
- We constantly buy 0day and Nday vulnerabilities and exploits. We do not pay for hypothetical vulnerabilities.
- Please provide a brief technical description of the vulnerabilities and exploits on our form to our
- e-mail: [email protected]
- Your vulnerability will be analyzed and evaluated by us within 48 hours. Remuneration can be paid in cash,
- bank transfers or anonymous transfers using crypto conversions. We are considering an additional premium
- for exclusive conditions for us in the form of additional quarterly payments to researchers before disclosure
- of the vulnerability.
- Prices 0days can be higher than indicated in the table all depends on the quality of the exploits, we are
- ready to negotiate the price on a bilateral basis.
- We also provide the service ESCROW service when both parties can not agree and do not trust each other.
- Agents and brokers are welcome, we pay high commissions for help in acquiring 0day vulnerabilities.
- We reserve the right to refuse to purchase your materials.
- If you have any counter proposals regarding the acquisition process, you can always contact us. We can organize
- a personal meeting with you in practical any country in the world to personally discuss all the issues personally.
- PRICING
- The price will depend on the technical information submitted. Once submitted we will respond with an offer which may be countered or accepted.
- In addition to vulnerabilities, we are interested in obtaining various research results, such as:
- - Deanonimization of TOR network resources
- - Bypassing ASLR, DEP, UAC and other security mechanisms
- - Attack vectors for remote code execution on devices via GSM, Bluetooth and WiFi
- - Vulnerabilities on mobile chipsets
- - Innovative detour of antiviruses
- - Other research results and technical information.
- ZERO SECURITY EXPLOIT TECHNICAL INFORMATION
- All questions should have the most detailed answers from this depends on what price we will offer you for your 0day exploit.
- 1. Item name :________________________________________________
- 2. Vendor Homepage:________________________________________________
- 3. Vulnerable Software:________________________________________________
- 4. Asking Price and availability of exclusive acquisition : ________________________
- 5. Affected OS: ________________________
- 6. Vulnerable Target application versions and reliability. If 32 bit only, is 64 bit vulnerable?
- List complete point release range. ________________________________________________
- 7. Tested, functional against target application versions, list complete point release range.
- Explain ________________________________________________
- 8. Does this exploit affect the current target version?
- [ ] Yes
- [ ] No
- 9. Targets can be found with google dork/shodan/censys?
- [ ] Yes
- [ ] No
- 10. Privilege Level Gained
- [ ] As logged in user (Select Integrity level below for Windows)
- [ ] Web Browser's default (IE - Low, Others - Med)
- [ ] Low
- [ ] Medium
- [ ] High
- [ ] Root, Admin or System
- [ ] Ring 0/Kernel
- [ ] Other
- 11. Minimum Privilege Level Required For Successful PE
- [ ] As logged in user (Select Integrity level below for Windows)
- [ ] Low
- [ ] Medium
- [ ] High
- [ ] N/A
- [ ] Other ________________________
- 12. Exploit Type (select all that apply)
- [ ] Remote code execution
- [ ] Privilege escalation
- [ ] Font based
- [ ] Sandbox escape
- [ ] Information disclosure (peek)
- [ ] Code signing bypass
- [ ] Persistency
- [ ] Other ________________________
- 13. Delivery Method
- [ ] Via web page
- [ ] Via file
- [ ] Via network protocol
- [ ] Local privilege escalation
- [ ] Other (please specify) ________________________
- 14. Bug Class
- [ ] memory corruption
- [ ] design/logic flaw (auth-bypass / update issues)
- [ ] input validation flaw (XSS/XSRF/SQLi/command injection, etc.)
- [ ] misconfiguration
- [ ] information disclosure
- [ ] cryptographic bug
- [ ] denial of service
- 15. Number of bugs exploited in the item: ________________________
- 16. Exploitation Parameters
- [ ] Bypasses ASLR
- [ ] Bypasses DEP / W ^ X
- [ ] Bypasses Application Sandbox
- [ ] Bypasses SMEP/PXN
- [ ] Bypasses EMET Version 5.52±
- [ ] Bypasses CFG (Win 8.1)
- [ ] N/A
- 17. Is ROP employed?
- [ ] No
- [ ] Yes (but without fixed addresses)
- - Number of chains included?
- ________________________
- - Is the ROP set complete?
- ________________________
- - What module does ROP occur from?
- ________________________
- 18. Does this item alert the target user?
- Explain ______________________________________________
- 19. How long does exploitation take, in seconds?
- 20. Does this item require any specific user interactions?
- 21. Any associated caveats or environmental factors? For example - does the exploit determine
- remote OS/App versioning,and is that required? Any browser injection method requirements?
- For files, what is the access mode required for success?
- 22. Does it require additional work to be compatible with arbitrary payloads?
- [ ] Yes
- [ ] No
- 23. Is this a finished item you have in your possession that is ready for delivery immediately?
- [ ] Yes
- [ ] No
- [ ] 1-5 days
- [ ] 6-10 days
- [ ] More: _______________________________
- 24. Does this exploit weaponized ?
- [ ] Yes
- [ ] No
- 25. Impact on framework (crashes, etc.) ____________________________________________________
- 26. Success rate (or number of necessary attempts) _________________________________________
- 27. Does this item support continuation of execution?
- 28. Description. Detail a list of deliverables including documentation.
- 29. Testing Instructions : _________________________________________________________________
- 30. Comments and other notes; unusual artifacts, other limitations, mitigations or other
- pieces of information : ________________________________________________________________
- -----BEGIN PGP PUBLIC KEY BLOCK-----
- mQGNBF+kNhkBDAC7LmMmoCI6oOgRMRacr+dFW6bBOAPYTDqalEbtf2LS3aicbqlE
- VvaeZJJNwZA5H7kGO7LrmDNXD59y3wxhtHgciK0B/sIh6+qSDd2F4SDMXut8nYPN
- WFnRlA4wXSbig9HIcXVlnyDSADpTdIlmalMvf0fd0Sx10vAWUuqjh2eM3bZraCwi
- 9IPy8alGDuyMD5+HDX5YWgln6m4HOHg2muVlSJ+6ztWOX19DXywpwOHQFld+LH6l
- gLGd3WJ/PrVV7lmBLmSFpqAJVtmSvxCTy+ItvorLY5KrEwNn2Tsomr7WboVLpoDC
- jlqnd1xr2lR4gCYNO1M6ssH7cbKoETxLm06oHhmRmm0MwOriFKdbaYP5wKU0YrJG
- PAZB647hwofAE786zIwR0Zdc0lWBk9XtVK2YnTswJW1+PIPmsO8sjGxhIyZ4dueI
- Jp5giu2oJp1xSi8Yh/mPKBrNgcuGqaJ1HLmeDiA84dn9ztApE41cy7TI8ZJhsQnj
- r18HKiYxAdPIPIkAEQEAAbQkSmFtZXMgR3JhbmRvZmYgPEpHcmFuZG9mZkAwLXNl
- Yy5uZXQ+iQHUBBMBCAA+FiEEduOVe3cX2HGW8u6LbTdnsBNScw0FAl+kNhkCGwMF
- CQPCUmcFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQbTdnsBNScw2trQv/T422
- ooaoDq8aS06oSJ+lLIoiCUhknQ1P6woixFCs8ganIwyqVIngaf9ypR1JnVwEMAsB
- gDpskMLIUEsXt0i/RRZH0ytF2KOaI/3430mnmum55iV6fT42L+psvn6D+By0zkkF
- 5DXTCy1pY4LkQdeaJAQ7C6nC7EfsqTeZizItTyRVI3IhbQk0DTAo1A3zPWMpXtYz
- 8CIviOgIHasbR8V52vUPcGcog7uOWnq25OxQn0xVJSGJz8lRhP6+YgbmG+AWFGEE
- DC0G4xINx4LlR2eVNS/lDfD5hdK+LzIAhuRdkqjcFKgzygBMGI4UY5Fd/9Ru2g+S
- gnr3j3T0sGyUmTXaSZV2VVBPBqOQNE4Av5ZAISRMqkO8yxvJzyNNdsV8+Qz9OWpY
- F7ZlFPyutvQaQx+Sexf+/JLyPie86qg4mlQo2AEBlxdzMtpS+mKcaRaukp94P8zh
- inF/7RQRaJOLcOibXba23Kooqn23EyEMZUX3qgA6Q6gUTdKfJu87hHnmbFxLuQGN
- BF+kNhkBDADZBC1lxh/9KkjNsmmOcdvrH7s9nxrrZx8qJzec1KA+gkX3ZUGlL+0E
- sKl6uVMioLpNjQcvgAmijBREU4LBWd12gHP1vsVxcpMH3iE4I2PJ87nQoDvEC+f1
- 3nAm9aEWtNlIVuO37AZku/gnfmFke/jWR5qZlcMukoCQR2oXdDM0SFoUN05ItxyW
- kh08H9WpqRSZRc/DBbAdvrOtXgHldk4cJrkedPLc5m8HYrWMfuaFvqAcO3mG2Xu2
- viEXrIo847lg6xgKCJIYn2LiG3dkrrPWpWquWZbRzoswQ68A/0esn9n2LcbGhG5X
- kc57x35vtx+OhWDv+Fy2fdy6pQXWYRFLwdj36w0FsdoxC5nu+SjI83rU28d0kLHs
- 4ii4cpdikp1DR96wow2XkJ7s7bUjnfFe72ackJDeLcoXvKrr5246FGfmGg9cDVzv
- KKfXCX52JjJ1rI8YFwL1lRgJW1adLB5yOlQIWi//QUNV+6kxpFwIU556H+qT7VbH
- eF/+79YdZIsAEQEAAYkBvAQYAQgAJhYhBHbjlXt3F9hxlvLui203Z7ATUnMNBQJf
- pDYZAhsMBQkDwlJnAAoJEG03Z7ATUnMNn44L/A51DXNDE0Jlu1rnyu0kP6R83M8g
- SJc2KHJaafy36Q3tISJzRWQ0vzUo1IbmbW7m0jU+rJ5PoRJ1gaS/r2L5eDJ66f4I
- oWXIkH4sKDTgLdQOhSIlJNe5w6J7bCUNbtDsowUvBFYdocFsMCollguIjlqITuRD
- 2iocHd7Qwg4YT6Y6wk30XNtl+ypr0u+fri/nxGRG/0dBr6eZfBIk1vdjWGasMOxL
- eSclr4I/loxh3qBYHlueEzeH3TWM6DQ83rj8CfRD6Bs8+x1JWt0XjtXDYC1DzMja
- KTzgqgIuJhKNYRciWHdQIYdpK8qnAkBsgqYR8khZfv1f8mKB/NJZbSv8O7KMRj+9
- uxrhxDWXSzJm+iSpGIz+mD6adWsN7hbVLXblrEDb2B92RKVwTRz3IE+EhTOWAiMM
- fx4M95b1drcrbavOGqhI5Wbm7IAqi4O8z7DFFdYqjZNRkGxsJCLLu3+mlHB/HXYL
- gZLGm8p2SKkOiv5fvsylyb9AEaYBczL35T6eDA==
- =losg
- -----END PGP PUBLIC KEY BLOCK-----
Add Comment
Please, Sign In to add comment