Month of bugs

{{short description|Strategy used by security researchers}}

{{Use dmy dates|date=July 2020}}

A month of bugs is a strategy used by security researchers to draw attention to the lax security procedures of commercial software corporations.

Researchers have started such a project for software products where they believe corporations have shown themselves to be unresponsive and uncooperative to security alerts. Responsible disclosure is not working properly, and then find and disclose one security vulnerability each day for one month.

Examples

The original "Month of Bugs" was the Month of Browser Bugs (MoBB) run by security researcher H. D. Moore.

Subsequent similar projects include:

  • The Month of Kernel Bugs (MoKB) which published kernel bugs for Mac OS X (now macOS), Linux, FreeBSD, Solaris and Windows, as well as four wireless driver bugs.
  • The Month of Apple Bugs (MoAB) conducted by researchers Kevin Finisterre and LMH which published bugs related to Mac OS X.
  • The Month of PHP Bugs sponsored by the Hardened PHP team which published 44 PHP bugs.

See also

References

{{reflist|colwidth=30em|refs=

{{cite web

|url = http://www.internetnews.com/security/article.php/3618126

|title = The Month of The Browser Bugs Begins

|work = InternetNews.com

|publisher = QuinStreet Inc.

|date = 5 July 2006

|access-date = 22 October 2010

|first1 = Sean Michael

|last1 = Kerner

}}

{{cite web

|url = http://www.gartner.com/DisplayDocument?doc_cd=144700&ref=g_homelink

|archive-url = https://web.archive.org/web/20120923125108/http://www.gartner.com/DisplayDocument?doc_cd=144700&ref=g_homelink

|url-status = dead

|archive-date = 23 September 2012

|title = Learn from 'Month of Kernel Bugs'

|work = Gartner archive

|publisher = Gartner Inc.

|date = 6 November 2006

|access-date = 22 October 2010

|first1 = Rich

|last1 = Mogull

}}

{{cite web

|url = http://www.eweek.com/c/a/Security/Month-of-Kernel-Bugs-Launches-with-Apple-WiFi-Exploit/

|title = Month of Kernel Bugs Launches with Apple Wi-Fi Exploit

|work = eWeek

|publisher = Ziff Davis Enterprise Holdings Inc.

|date = 1 November 2006

|access-date = 22 October 2010

|first1 = Ryan

|last1 = Naraine

}}

{{cite web

|url = http://www.zdnet.co.uk/news/security-threats/2006/11/02/apple-wireless-flaw-revealed-39284508/

|title = Apple wireless flaw revealed

|work = ZDNet

|publisher = CBS Interactive

|date = 2 November 2006

|access-date = 22 October 2010

|first1 = Joris

|last1 = Evers

}}

{{cite web

|url = http://www.pcworld.com/article/128282/apple_bughunt_begins.html

|title = Apple Bug-Hunt Begins

|work = PC World

|publisher = PCWorld Communications, Inc.

|date = 20 December 2006

|access-date = 22 October 2010

|first1 = Robert

|last1 = McMillan

}}

{{cite web

|url = https://www.theregister.co.uk/2006/12/20/month_of_apple_bugs/

|title = Month of Apple bugs planned for January

|work = The Register

|publisher = The Register

|date = 20 December 2006

|access-date = 22 October 2010

|first1 = John

|last1 = Leyden

}}

{{cite web

|url = http://securitywatch.eweek.com/apple/coming_in_january_month_of_apple_bugs.html

|title = Coming in January: Month of Apple Bugs

|work = eWeek Security Watch

|publisher = Ziff Davis Enterprise Holdings Inc.

|date = 19 December 2006

|access-date = 22 October 2010

|first1 = Ryan

|last1 = Naraine

}}

{{cite web

|url = http://www.eweek.com/c/a/Security/Month-of-PHP-Bugs-Begins/

|title = Month of PHP Bugs Begins

|work = eWeek

|publisher = Ziff Davis Enterprise Holdings Inc.

|date = 3 March 2007

|access-date = 22 October 2010

|first1 = Brian

|last1 = Prince

}}

{{cite web

|url = http://www.zdnet.com/blog/security/flaw-trifecta-kicks-off-month-of-php-bugs/107

|archive-url = https://web.archive.org/web/20100812031303/http://www.zdnet.com/blog/security/flaw-trifecta-kicks-off-month-of-php-bugs/107

|url-status = dead

|archive-date = 12 August 2010

|title = Flaw trifecta kicks off Month of PHP bugs

|work = ZDNet

|publisher = CBS Interactive

|date = 1 March 2007

|access-date = 22 October 2007

|first1 = Ryan

|last1 = Naraine

}}

{{cite web

|url = https://www.zdnet.com/topic/security/?tag=mantle_skin;content

|title = Controversial 'month of bugs' getting security results

|work = ZDNet

|publisher = CBS Interactive

|date = 4 May 2007

|access-date = 22 October 2010

|first1 = Ryan

|last1 = Naraine

}}

}}

Further reading

{{refbegin}}

  • {{Cite web |last1=McMillan |first1=Robert |date=17 March 2007 |title=Hackers Promise Month of MySpace Bugs |url=http://www.pcworld.com/article/129933/hackers_promise_month_of_myspace_bugs.html |work=PC World |access-date=22 October 2010}}

{{refend}}