Metasploit offers bounty for exploits
The Metasploit team is looking for exploits for 30 security vulnerabilities, for which it is offering bounties of up to $500 each. The vulnerabilities in question have already been fixed by the respective vendors, but as most were reported directly to those vendors, specific details were never made public. Exploit developers and contributors can claim a vulnerability, which gives them one week to work on a module and deliver a suitable exploit.
Should they fail to do so, the exploit will no longer be reserved and will be open again to the community. The top five vulnerabilities for which the team is offering the maximum bounty include a vulnerability affecting DNS name queries in Windows; this can be exploited by an attacker on the same network using crafted broadcast packets to take control of another computer. The team is also offering the maximum bounty for vulnerabilities in Windows' GDI+ library, Lotus Notes, IBM Tivoli Directory Server and Google Chrome.