Month of bugs

Last updated

A month of bugs is a strategy used by security researchers to draw attention to the lax security procedures of commercial software corporations.

Contents

Researchers have started such a project for software products where they believe corporations have shown themselves to be unresponsive and uncooperative to security alerts. Responsible disclosure is not working properly, and then find and disclose one security vulnerability each day for one month.

Examples

The original "Month of Bugs" was the Month of Browser Bugs (MoBB) run by security researcher HD Moore. [1]

Subsequent similar projects include:

See also

Related Research Articles

Microsoft Windows, commonly referred to as Windows, is a group of several proprietary graphical operating system families, all of which are developed and marketed by Microsoft. Each family caters to a certain sector of the computing industry. Active Microsoft Windows families include Windows NT and Windows IoT; these may encompass subfamilies,. Defunct Microsoft Windows families include Windows 9x, Windows Mobile, and Windows Phone.

Adobe Acrobat Set of application software to view, edit and manage files in Portable Document Format (PDF)

Adobe Acrobat is a family of application software and Web services developed by Adobe Inc. to view, create, manipulate, print and manage files in Portable Document Format (PDF).

Windows 7 Personal computer operating system by Microsoft released in 2009

Windows 7 is an operating system that was produced by Microsoft and released as part of the Windows NT family of operating systems. It was released to manufacturing on July 22, 2009, and became generally available on October 22, 2009. It is the successor to Windows Vista, released nearly three years earlier. It remained an operating system for use on personal computers, including home and business desktops, laptops, tablet PCs and media center PCs, and itself was replaced in November 2012 by Windows 8, the name spanning more than three years of the product. Until April 9, 2013, Windows 7 RTM provided content such as security updates, software updates, PC driver updates and technical support, after which installation of Service Pack 1 is required for users to receive support and updates. Windows 7's server counterpart, Windows Server 2008 R2, was released at the same time. The last supported version of Windows based on this operating system was released on July 1, 2011, entitled Windows Embedded POSReady 7. On January 12, 2016, Microsoft ended support for Internet Explorer versions older than Internet Explorer 11 on Windows 7. Extended support ended on January 14, 2020, over ten years after the release of Windows 7, after which the operating system ceased receiving further support or security updates to most users, and all PCs that blocks Windows Update on Windows 7 versions newer than KB4499164 released in May 2019 displays a full-screen upgrade warning notification with an information page link starting from January 15, 2020. A support program is currently available for enterprises, providing security updates for Windows 7 for up to four years since the official end of life. However, Windows Embedded POSReady 7, the last Windows 7 variant, continues to receive security updates until October 2021.

Ziff Davis American publisher and Internet company owned by j2 Global

Ziff Davis, LLC, known as Ziff Davis (ZD), is an American media conglomerate founded in 1927. Originally an advertising and publishing firm, they primarily produced magazines and comic books for the majority of their history, briefly entered the television market in the 1970s and 1980s, and in the 1990s, fully transitioned to digital media, affiliate marketing and technology transfer; today all of their subsidiaries are online properties. Among their former and current brands are Popular Photography, science fiction magazine Amazing Stories, computer publication PC Magazine, ZDNet, internet gaming review site IGN, media platform Mashable, and many others.

ZDNet Business technology news website

ZDNet is a business technology news website owned and operated by Red Ventures, along with TechRepublic. The brand was founded on April 1, 1991, as a general interest technology portal from Ziff Davis and evolved into an enterprise IT-focused online publication.

Linux adoption is the adoption of Linux computer operating systems (OS) by households, nonprofit organizations, businesses, and governments.

Faronics Software company in Canada

Faronics Corporation is a privately held software company with offices in Vancouver, British Columbia, Canada, Pleasanton, California, United States, Singapore and Bracknell, UK. Faronics develops computer software for multi-user IT environments.

<i>Just Cause</i> (video game) 2006 action-adventure game

Just Cause is a 2006 third-person action-adventure game set in an open world environment. It is developed by Swedish developer Avalanche Studios and published by Eidos Interactive, and is the first game in the Just Cause series. It was released for Microsoft Windows, PlayStation 2, Xbox, and Xbox 360. The area explored during the game is described as being over 1,024 km2 (395 sq mi) in size, with 21 story missions and over 300 side missions to complete.

Blue Pill is the codename for a rootkit based on x86 virtualization. Blue Pill originally required AMD-V (Pacifica) virtualization support, but was later ported to support Intel VT-x (Vanderpool) as well. It was designed by Joanna Rutkowska and originally demonstrated at the Black Hat Briefings on August 3, 2006, with a reference implementation for the Microsoft Windows Vista kernel.

Android (operating system) Mobile operating system based on a modified version of the Linux kernel and other open source software

Android is a mobile operating system based on a modified version of the Linux kernel and other open source software, designed primarily for touchscreen mobile devices such as smartphones and tablets. Android is developed by a consortium of developers known as the Open Handset Alliance and commercially sponsored by Google. It was unveiled in November 2007, with the first commercial Android device launched in September 2008.

CNET American media website about technology and consumer electronics

CNET is an American media website that publishes reviews, news, articles, blogs, podcasts, and videos on technology and consumer electronics globally, owned by Red Ventures since 2020. Founded in 1994 by Halsey Minor and Shelby Bonnie, it was the flagship brand of CNET Networks and became a brand of CBS Interactive through that unit's acquisition of CNET Networks in 2008, which was the previous owner prior to October 30, 2020. CNET originally produced content for radio and television in addition to its website and now uses new media distribution methods through its Internet television network, CNET Video, and its podcast and blog networks.

A mobile operating system is an operating system for mobile phones, tablets, smartwatches, 2-in-1 PCs, smart speakers, or other mobile devices. While computers such as typical laptops are 'mobile', the operating systems used on them are generally not considered mobile ones, as they were originally designed for desktop computers that historically did not have or need specific mobile features. This distinction is becoming blurred in some newer operating systems that are hybrids made for both uses.

Symantec Endpoint Protection Computer security software

Symantec Endpoint Protection, developed by Broadcom Inc., is a security software suite that consists of anti-malware, intrusion prevention and firewall features for server and desktop computers. It has the largest market-share of any product for endpoint security.

David Gewirtz

David Allen Gewirtz is an American journalist, author, and U.S. policy advisor who has written more than 900 articles about technology, competitiveness, and national security policy. Gewirtz was featured on The History Channel television special The President's Book of Secrets, which detailed secret information privy only to the President of the United States. He currently serves as director of the U.S. Strategic Perspective Institute.

Windows 8 Personal computer operating system by Microsoft released in 2012

Windows 8 is an operating system that was produced by Microsoft, released as part of the Windows NT family of operating systems. The product was released to manufacturing on August 1, 2012, and generally to retail on October 26 of the same year, succeeding Windows 7.

Pwn2Own is a computer hacking contest held annually at the CanSecWest security conference. First held in April 2007 in Vancouver, the contest is now held twice a year, most recently in November 2019. Contestants are challenged to exploit widely used software and mobile devices with previously unknown vulnerabilities. Winners of the contest receive the device that they exploited and a cash prize. The Pwn2Own contest serves to demonstrate the vulnerability of devices and software in widespread use while also providing a checkpoint on the progress made in security since the previous year.

<i>SmartPlanet</i> Online magazine

SmartPlanet was an online magazine that covered clean technology and information technology as it related to healthcare, science, transportation, corporate sustainability, architecture, and design. It was part of the business portfolio of CBS Interactive that included BNET and ZDNet and was known for its daily coverage of the technology and energy industries. It stopped publishing on June 30, 2014.

Office 365 Microsoft software product

Office 365 is a line of subscription services offered by Microsoft as part of the Microsoft Office product line. The brand encompasses plans that allow use of the Microsoft Office software suite over the life of the subscription, as well as cloud-based software-as-a-service products for business environments, such as hosted Exchange Server, Skype for Business Server, and SharePoint, among others. All Office 365 plans include automatic updates to their respective software at no additional charge, as opposed to conventional licenses for these programs—where new versions require purchase of a new license.

Windows 10 Personal computer operating system by Microsoft released in 2015

Windows 10 is a series of operating systems developed by Microsoft and released as part of its Windows NT family of operating systems. It is the successor to Windows 8.1, released nearly two years earlier, and was released to manufacturing on July 15, 2015, and broadly released for the general public on July 29, 2015. Windows 10 was made available for download via MSDN and Technet, and as a free upgrade for retail copies of Windows 8 and Windows 8.1 users via the Windows Store, and Windows 7 users via Windows Update. Windows 10 receives new builds on an ongoing basis, which are available at no additional cost to users, in addition to additional test builds of Windows 10, which are available to Windows Insiders. Devices in enterprise environments can receive these updates at a slower pace, or use long-term support milestones that only receive critical updates, such as security patches, over their ten-year lifespan of extended support.

References

  1. Kerner, Sean Michael (5 July 2006). "The Month of The Browser Bugs Begins". InternetNews.com. QuinStreet Inc. Retrieved 22 October 2010.
  2. Mogull, Rich (6 November 2006). "Learn from 'Month of Kernel Bugs'". Gartner archive. Gartner Inc. Retrieved 22 October 2010.
  3. Naraine, Ryan (1 November 2006). "Month of Kernel Bugs Launches with Apple Wi-Fi Exploit". eWeek . Ziff Davis Enterprise Holdings Inc. Retrieved 22 October 2010.
  4. Evers, Joris (2 November 2006). "Apple wireless flaw revealed". ZDNet . CBS Interactive . Retrieved 22 October 2010.
  5. McMillan, Robert (20 December 2006). "Apple Bug-Hunt Begins". PC World . PCWorld Communications, Inc. Retrieved 22 October 2010.
  6. Leyden, John (20 December 2006). "Month of Apple bugs planned for January". The Register . The Register. Retrieved 22 October 2010.
  7. Naraine, Ryan (19 December 2006). "Coming in January: Month of Apple Bugs". eWeek Security Watch. Ziff Davis Enterprise Holdings Inc. Retrieved 22 October 2010.
  8. Prince, Brian (3 March 2007). "Month of PHP Bugs Begins". eWeek . Ziff Davis Enterprise Holdings Inc. Retrieved 22 October 2010.
  9. Naraine, Ryan (1 March 2007). "Flaw trifecta kicks off Month of PHP bugs". ZDNet . CBS Interactive . Retrieved 22 October 2007.
  10. Naraine, Ryan (4 May 2007). "Controversial 'month of bugs' getting security results". ZDNet . CBS Interactive . Retrieved 22 October 2010.

Further reading