Quantcast
RSS

Security Vulnerabilities for Sale to the Highest Bidder

A vulnerability that affects SAP's MaxDB hasn't garnered any bids yet on a controversial auction site for computer vulnerabilities.

If exploited, the problem would let an attacker access the entire contents of the database, according to Wabisabilabi, which is offering proof-of-concept code and details on its vulnerability auction site. Bidding starts at €3,000 (US$4,407).

"The result can be scary," said Wabisabilabi on its blog.

Wabisabilabi, based in Switzerland, started its vulnerability auction site in July on the premise that security researchers aren't adequately compensated for their work and could sell zero-day vulnerabilities on the black market.

Wabisabilabi's site lets security researchers submit vulnerabilities for auction. Wabisabilabi said it will only sell vulnerabilities to qualified researchers who aren't going to do anything malicious. Nonetheless, the security community has questioned whether Wabisabilabi's business premise is ethical.

According to Wabisabilabi's blog, the MaxDB vulnerability is easy to exploit. It affects Linux machines running the latest version of MaxDB, 7.6.00.37, and Windows machines running version 7.6.00.37. The problem could also affect other versions of the database.

An attacker could send a specially crafted request to the listening port of the vulnerable MaxDB service. The command would be executed with the credentials of the user running the process. Then, an attacker could "dump the content of the whole database," Wabisabilabi wrote.

Wabisabilabi said it's rare to find a database running open on the Internet, but more common within corporate intranets.

An SAP official contacted in Germany did not have an immediate comment.

Was this article useful? Yes 0 No 0
Add Yours

Comments Readers reply with their ideas and expertise.

Subscribe to this discussion via email or RSS
  • What do you think?

  • Great year-end deals
    for small business!
  • Get 24/7 live remote AT&T Tech Support 360* service along with select Lenovo* PCs (with Intel® Core™ 2 Duo processors) and save up to 200!

    Learn more

  • HP EliteBook* 6930p Notebook with Intel® vPro™ technology and a free HP Basic Docking Station - $641 instant savings!

    Learn more

Business News Daily

Get the latest technology news that's important to you and your business, fresh seven days a week.

Featured Webcasts

Free Whitepapers

Software and Services Whitepapers from PC World

More whitepapers »

Whitepaper Alerts

Get updates on white papers, case studies, and spotlights on tech products and solutions for your business.

PC World's Marketplace

Sponsored Links