Jump to content
Matt

Hackers may cash in when XP is retired

Recommended Posts

Posted

Hackers could find themselves in the catbird seat on April 8, 2014 -- the day Microsoft plans to stop patching Windows XP. As security expert Jason Fossen sees it, those who have zero-day exploits for XP will bank them until that day and then sell them to crooks or loose them themselves on unprotected PCs.

It's simply economics at work, said Fossen, a trainer for the SANS Institute since 1998.

"The average price on the black market for a Windows XP exploit is $50,000 to $150,000, a relatively low price that reflects Microsoft's response," said Fossen. When a new vulnerability -- dubbed a "zero-day" -- is detected, Microsoft investigates, pulls together a patch and releases it to XP users.

But the price will go up when Microsoft stops patching its aged operating system.

Fossen acknowledged that there really aren't any precedents to back up his speculation, because the last time Microsoft retired an operating system was in July 2010, when it pulled the plug on Windows 2000, which wasn't nearly as widely used as XP is.

Computerworld has projected that Windows XP will still run 33% to 34% of the world's PCs at the end of April 2014.

HD Moore, creator of the popular Metasploit penetration testing toolkit and chief security officer at security company Rapid7, agreed that XP hacks would become more valuable after the operating system's retirement in April 2014, but he contended that all Windows vulnerabilities would jump in value at that time.

Source ComputerWorld.Com

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...