Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Top Posters

Who's Online (0)

Powered by Vanilla. Made with Bootstrap.
12-year-old finds critical Firefox flaw, earns $3,000 bounty
  • undead
    Posts: 822
    The security researcher who found and reported this critical buffer overflow and memory corruption vulnerability in Mozilla’s Firefox browser is none other than Alex Miller, a 12-year-old boy who earned a $3,000 bounty for his discovery.

    http://i.zdnet.com/blogs/alex_miller.png

    According to the San Jose Mercury News, Miller (right) was motivated to search for Firefox security holes after Mozilla increased its bug bounty from $500 to $3,000.

    The seventh grader, described as a “Firefox loyalist,” had previously reported a Firefox vulnerability but that one did not qualify for the cash payout.

    Alex returned to the computer and his exploration. By Alex’s estimation he spent about 90 minutes each day for about 10 days until he spotted it–a flaw in the memory of the running program.

    The vulnerability, which can be exploited to crash a victim’s browser and potentially run arbitrary code on their computer, was patched this week in:

    * Firefox 3.6.11
    * Firefox 3.5.14

    It also affects:

    * Mozilla’s Thunderbird 3.1.5
    * Thunderbird 3.0.9
    * SeaMonkey 2.0.9

    Source:
    www.zdnet.com
  • George
    Posts: 707
    That would of been the best day of his short life.
  • Xin
    Posts: 3,251
    Wow that guy is 3l33t! Good on him
    Xin
  • George
    Posts: 707
    The question is, $3,000 for him or his parents...

    It's not a huge amount of money though, nevertheless I wouldn't say no to it.
  • Xin
    Posts: 3,251
    Yeah the sad thing is that if he sold it in the blackhat world he could have earnt so much more money than that
    Xin
  • D0WNGRADE
    Posts: 220
    Nice! I would love to have an extra $3K. lol
  • GameOver
    Posts: 675
    Excellent guy! :)
  • mandi
    Posts: 207
    amazing guy :) well done for your work,from next time sell those things on black markets ..
  • undead
    Posts: 822
    I agree with you xinapse and mandi