Remix.run Logo
kuroguro a day ago

Likely referencing https://www.crowdfense.com/exploit-acquisition-program/

Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zero...

These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full payment or not for something similar.

bink a day ago | parent | next [-]

I work in the field and I just cannot believe anyone would pay that much for a Word Press exploit. People pay money for iOS or Android because there is valuable information stored on devices running those operating systems. There's absolutely nothing of value on any Word Press site. The only possible reason I can think of is for a watering hole attack, but that would require a second exploit that would be worth far more (and they aren't).

tedggh a day ago | parent | next [-]

I currently work for a federal contractor including the DoD as their customer, using Wordpress as their main website. You would think there’s no sensitive information there, but some times all it takes is enough information about someone and their team to impersonate that person and gain access to an email thread, file sharing system or even an access card to a building. Never underestimate incompetence.

soulofmischief 20 hours ago | parent [-]

And never underestimate the competence of others.

kulahan 15 hours ago | parent [-]

lol, a big part of security is being smart enough to never challenge the bored…

grugq 18 hours ago | parent | prev | next [-]

Bulk reply to all the people replying.

bink is correct. The people who buy exploits are governments. There is very little interest in Wordpress or indeed any target that isn't a browser or a mobile. Browsers and mobiles are the only things that are perennially useful to an intelligence agency. Those two are reliable access vectors for the vast majority of things that interest government organisations.

strictnein 16 hours ago | parent | next [-]

Are they only buying browser RCEs or are they also interested in RCEs deliverable via browser?

ex: Target hits website -> site delivers RCE for some software that is on the target's system

dcrazy 16 hours ago | parent | prev | next [-]

Aren’t WP exploits valuable for watering hole attacks?

strictnein 16 hours ago | parent | next [-]

You don't need an RCE for that though. There's a lot of vulnerable plugins deployed everywhere.

dcrazy 14 hours ago | parent [-]

Ok, but an RCE in WP Core still seems pretty dang valuable, especially if you want to hit non-commercial websites that are less likely to have as many plugins installed?

illliillll 15 hours ago | parent | prev [-]

You already owned the WordPress admin with your browser 0day, you don’t care if WordPress is secure or not.

mschuster91 17 hours ago | parent | prev [-]

> There is very little interest in Wordpress

I'd disagree here. Still 41% of all sites use Wordpress [1]... and that means a lot of targets, and a lot of ways to target them. Your good ole' deface/ransomware extortion scheme, leaking data supposed to be confidential (such as account lists), trusted spreaders for exploits, or the latest hit, bets on "prediction markets" that have some Wordpress site set as oracle. People are willing to screw around with airport weather stations to manipulate bets [2], it's not that much of a stretch to assume such incentives would also apply for website hackers.

[1] https://www.wpzoom.com/blog/wordpress-statistics/

[2] https://edition.cnn.com/2026/04/23/europe/france-weather-sen...

strictnein 16 hours ago | parent [-]

Plenty of underground forums sell exploits for people to do stuff like that, but you're talking $200, not a theoretical $500k.

You also don't need an RCE for 99% of that.

JSR_FDED 18 hours ago | parent | prev | next [-]

Remember the Panama papers? That was a Wordpress hack.

technion 14 hours ago | parent | prev | next [-]

Compromising a crappy wordpress site means compromising mailbox credentials.

https://lolware.net/blog/2020-09-02-autodiscover-circus/

marysol5 a day ago | parent | prev | next [-]

Surprising amount of gov use WP as a CMS on their websites. So it's not that far off.

foco_tubi 18 hours ago | parent | prev | next [-]

> There's absolutely nothing of value on any Word Press site

This is just 100% an incorrect assumption. Even just an e-commerce site running Woo has troves of potentially valuable customer data. Not to mention whatever else might be on the server, or what that server is connected to...

apercu 16 hours ago | parent | prev | next [-]

>There's absolutely nothing of value on any Word Press site.

I would hope not, but I’d be surprised if that were true across the millions(?) of Wordpress sites?

madaxe_again 21 hours ago | parent | prev [-]

There’s a server running behind a Wordpress site. If you have RCE, you can run whatever arbitrary code you like there - mine crypto, run a botnet, all sorts of fun and profitable stuff. Hey, you can even make the site make the site’s users your unwitting hosts, too. You don’t go hack a Wordpress site, you go grab a few hundred thousand of them and do industrial scale crimes.

tptacek a day ago | parent | prev | next [-]

[flagged]

intheitmines 21 hours ago | parent | next [-]

Is there anywhere currently buying that you can approach without a pre-existing relationship?

StrauXX a day ago | parent | prev | next [-]

Of course it is. It just no longer exists.

tptacek a day ago | parent [-]

Oh, you've done business with them then? Know someone who has?

cmeacham98 a day ago | parent | next [-]

Yes actually, I know someone who did business with them many years ago (before the advent of LLMs), although for a smaller sum than the advertised top payouts (the vulnerability they had was much less important).

Why post these random unsubstantiated claims on HN?

close04 21 hours ago | parent [-]

> Why post these random unsubstantiated claims on HN?

To show everyone the Gell-Mann amnesia effect in action.

When HN top karma poster and security professional posts something like this, doubles down, and can’t even be bothered to support it in any way (I’m open to learning and changing my opinion) it completely blurs the line going into social media influencer. Quantity over quality.

parl_match 13 hours ago | parent | prev | next [-]

Yes, I have briefly done business with them as well. We also worked with Bekrar and Vupen briefly. Albeit, it was done through a broker. The second time around, we exited negotiations.

Just because they're exclusive about their clients doesn't mean they're not real. Their impact and effectiveness is a separate topic though. I don't think they're still actively operating or taking new clients, at least.

btw: "Oh, so you've done x?" What a snarky and confrontational way to ask someone something. Especially when it's asserting a well documented company and person is "not real".

tptacek 9 hours ago | parent [-]

Did you get mid-high 5 figures for a serverside vulnerability? I hear the Russians are paying $300k for Postfix! But the UAE might pay $400k through Crowdfense. These numbers are definitely real. How could they not be? They're right there on a web page.

StrauXX a day ago | parent | prev | next [-]

I do, as a matter of fact.

monster_truck 20 hours ago | parent | prev | next [-]

My lawyer says I can't answer that

jnbcxdrun a day ago | parent | prev [-]

[dead]

ofjcihen a day ago | parent | prev [-]

Why would you reply with something completely unsubstantiated that anyone in security at that time worth their salt would be able to call you out on and then in subsequent comments call people liars for insisting it did, in fact, exist?

I’m just baffled.

dadrian 18 hours ago | parent [-]

The pricelist was a marketing stunt.

Hizonner a day ago | parent | prev [-]

Why would anybody trust criminals to pay them over time?

idiotsecant a day ago | parent [-]

Because if they don't other people will hear they don't pay and won't sell them 0days

nativeit a day ago | parent [-]

How long do you figure a criminal reputation typically needs/wants to last? I have always been skeptical of “black market credit ratings”. If you happen to build one up, it’s likely only in order to rip someone off at a higher price and cash in the value of it. It’s not like you’ll need that good rep for your retirement.

applfanboysbgon a day ago | parent [-]

ShinyHunters has been "in business" since 2019 and it is their reputation that resulted in eg. Canvas paying their ransom this year. Without that reputation, it is unlikely a large-scale ransom would have been paid, because the reputation is what gives them credibility that paying the ransom will actually result in the promise being upheld.