I have found a zero day on a server that the local hacking league uses for most of their scenarios during competitions. It isn't huge or anything but it does help me get in and I am hoping to get it working with some MSF payload. My question is, is it ethical for me to keep this zero day a secret so I can use it during my competition or should I report it now?
Forum Thread: Is It Ethical to Keep a Zero Day for a Competition?
- Hot
- Active
-
Forum Thread: 12 Ways How to Hack Any Social Network and Protect Yourself 2018 1 Replies
3 hrs ago -
Metasploit Error: Handler Failed to Bind 40 Replies
3 days ago -
Forum Thread: How to Know if You Are a Script Kiddie? 9 Replies
2 wks ago -
Forum Thread: How to Identify and Crack Hashes 8 Replies
2 wks ago -
Forum Thread: How to Hack School Website 8 Replies
3 wks ago -
Forum Thread: Whenever I Try "Airmon-Ng Start wlan0" There's an Error? 16 Replies
3 wks ago -
Forum Thread: How to Fix 'Failed to Detect and Mount CD-ROM' Problem When Installing Kali Linux 14 Replies
3 wks ago -
Forum Thread: Awesome Keylogging Script - BeeLogger 30 Replies
1 mo ago -
Forum Thread: How to Hack Android Phone Using Same Wifi 27 Replies
1 mo ago -
Forum Thread: Complete Guide to Creating and Hosting a Phishing Page for Beginners 48 Replies
1 mo ago -
Forum Thread: Create and Use Android/Meterpreter/reverse_tcp APK with Msfvenom? 121 Replies
1 mo ago -
How to: Minecraft DoS'Ing with Python. 1 Replies
2 mo ago -
Forum Thread: HELP I Created an Apk for Hacking My Phone Using Kali Linux in Virtual Box How Can I Install That Apk on My Phone 17 Replies
2 mo ago -
Forum Thread: Tools for Beginner Hacker 3 Replies
2 mo ago -
Forum Thread: How to Embed an Android Payload in an Image? 9 Replies
3 mo ago -
Forum Thread: Metasploit reverse_tcp Handler Problem 46 Replies
3 mo ago -
Forum Thread: HACK ANDROID with KALI USING PORT FORWARDING(portmap.io) 11 Replies
3 mo ago -
Forum Thread: Fix Initramfs Problem 5 Replies
3 mo ago -
Forum Thread: Kali Wont Start, Stuck at Kali Login: 21 Replies
4 mo ago -
Forum Thread: How to View Your Child's What's App And Many More! 3 Replies
4 mo ago
-
How To: Brute-Force Nearly Any Website Login with Hatch
-
How To: Gain SSH Access to Servers by Brute-Forcing Credentials
-
How To: Use Burp & FoxyProxy to Easily Switch Between Proxy Settings
-
How To: Make Spoofed Calls Using Any Phone Number You Want Right from Your Smartphone
-
How To: Exploit EternalBlue on Windows Server with Metasploit
-
How To: Crack Password-Protected Microsoft Office Files, Including Word Docs & Excel Spreadsheets
-
How To: Check if Your Wireless Network Adapter Supports Monitor Mode & Packet Injection
-
How to Hack Wi-Fi: Cracking WPA2 Passwords Using the New PMKID Hashcat Attack
-
How To: Enumerate SMB with Enum4linux & Smbclient
-
How To: Scan Websites for Interesting Directories & Files with Gobuster
-
How To: Crack SSH Private Key Passwords with John the Ripper
-
How To: Dox Anyone
-
How To: Scan for Vulnerabilities on Any Website Using Nikto
-
How To: Crack Shadow Hashes After Getting Root on a Linux System
-
How to Hack Wi-Fi: Stealing Wi-Fi Passwords with an Evil Twin Attack
-
How To: Manually Exploit EternalBlue on Windows Server Using MS17-010 Python Exploit
-
How To: 4 Ways to Crack a Facebook Password & How to Protect Yourself from Them
-
How To: Perform an Attack Over WAN (Internet)
-
How To: Top 10 Things to Do After Installing Kali Linux
-
How To: Find Identifying Information from a Phone Number Using OSINT Tools
3 Responses
Ethical hackers keep their 0day to themselves all the time. Check out this killer "0day" that a hacker saved until Blackhat this year: "Funtenna"
I would say the benefits of keeping it to yourself for a convention is more "fame or fortune" motivation but there are plenty of ethical reasons to keep 0 day to yourself.
Namely, even if you aren't the first to know about it, it isn't widely known so it isn't being widely exploited. Maybe you want to keep it to yourself or a small group to develop a patch first and then release the exploit. Maybe you release the exploit to persuade (coerce) the vendor to release a patch for their software.
Bottom line is, it's up to you and your own definition of right or wrong. When yo do release it, please write a tutorial.
It is still in the early stages, I haven't even done more than manually do the exploit. If I get it good enough I can post it here.
it might not be a zero day anymore when the competition comes.
Share Your Thoughts