Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Selling 0-Days to Governments and Offensive Security Companies

Black Hat via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the intricacies of selling 0-day vulnerabilities to governments and offensive security companies in this 50-minute Black Hat conference talk. Gain insight into the operations of Q-recon, a vulnerability brokerage company, and learn about the fascinating process of vulnerability trading. Discover the differences between government and corporate clients, various researcher types, and the intricacies of the vulnerability market. Delve into topics such as payment structures, warranty models, terms of sale, market demand, validation processes, and legal considerations. Understand the role of vulnerability brokers, their services, and the benefits of working with them. Conclude with practical advice on getting started in the field, participating in CTFs, and accessing free services for client validation.

Syllabus

Welcome
Introduction
White Hats
Difference between governments and companies
Different types of researchers
How does the chart work
What we learned
What is the process
Payment
Warranty and Sell Model
Terms of Sale
Market Demand
Validation
Backend
Validation Period
Test Environment
Freeze Payments
Property Rights
Support
Governing Law
Contacting Clients
Official Point of Contact
Government
Pros and Cons
Personal Connection
Vulnerability Brokers
Services Map
Benefits of Working with Brokers
Brokers Fees
Summary
Feedbacks
Biggest Take Away
Start Working
CTFs
Get Help
Free Services
Client Validation

Taught by

Black Hat

Reviews

Start your review of Selling 0-Days to Governments and Offensive Security Companies

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.