Hey Folks,
This is a call out to all security experts and hackers, inviting you to take part in a pre-launch eMunie network stress and hack test with PRIZES!!
We're getting pretty close to our next OB in a couple of weeks, hopefully followed soon after by our V1.0 launch, thus the time has come to weed out any possible exploits or issues with the system before they can cause loss or harm.
I consider myself a good developer, I try to cover all angles of any scenario as much as possible. That said I'm not naive, nor have a galaxy sized ego which results in thinking my code is the best, most secure, or can never be exploited....I am human after all, humans miss things and make mistakes. I expect there to be issues, and the purpose of this test is not to prove there aren't any, but to find any that are and fix them!
So, as we tend to do over here, I would like to set another industry first.
I'm inviting anyone that thinks they have the means, to perform attacks on the network in an attempt to cause disruption in a test environment initially, which will be setup for this task, and also in a future open beta. The date for these tests to start is not yet planned, but should be within the next 4 weeks (depending on how many applicants and furnishing selected candidates with the needed information to perform thorough attacks).
Disruption is anything from an outright DDOS of the entire network, to message sniffing, double spends and everything in between. I will provide detailed information regarding the packets and data structures sent around the network, the topology, and various other details to assist in any disruption attempts. Please do not ask for source code, as stated many times before, eMunie is and will remain closed source for at least 6 months post launch.
There will be limited places available for this task, 2 reasons.
1. I don't want to manage 1000's of egos
2. 1000's of people cross flooding attacks on the network with only a small number of "honest" nodes will of course cause disruption and make it harder to pinpoint the real exploits.
Those wishing to take part please communicate to me either via PM here, email
[email protected] or you can add me to Skype on thengonet ... if you are paranoid and would like to communicate via more secure means, please express such in your initial contact, I'm happy to download and install any required software to do so.
A short list of candidates will be constructed, consisting of around 20 or for the initial test environment. As we plan to do a few of these before launch, these numbers will increase over time and subsequent contests will be held.
Bounties are organized as follows:
- 5 BTC for most serious disruption
- 3 BTC for 2nd most serious disruption
- 1 BTC for 3rd most serious disruption
- 0.25-0.5 for other disruptions classified as threats
To claim a bounty you must provide proof of your successful attack and provide full details on how it was achieved so that we can replicate it. If the attack can not be replicated, or sufficient details are not provided then the bounty will not be paid for that threat and the subsequent most serious threat will take that bounty.
Decisions on the severity of discovered exploits will be made by forum members both here and at eMunie in a results thread. No accounts registered on either forum after 1st September 2014 will be allowed to vote, and those votes will be discounted.
NOTE: If no disruptions are deemed severe enough to warrant the top 3 bounties, those bounties will be spread around any minor disruptions.
Finally, this is a self-moderated thread as it is a serious topic for a serious project. I do not want it descending into a cock waving contest, about who's hacked what, and how many chicks you were able to lay because of bragging about it