June 2016 Summaries
7 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
When building a bounty brief, it's just as important to specify what you don't want researchers to test for as what you do want them to test for. This helps respect researchers' time and effort by excluding common issues like low-impact bugs, intended functionality that could be misinterpreted as a vulnerability, known issues that are not worth fixing before the program launches, accepted risks that are not worth rewarding, and issues resulting from pivoting. By explicitly noting these exclusions, you can save both yours and researchers' time, provide a better experience for researchers, and build a positive relationship with them. This is crucial to create a successful bounty program where researchers feel encouraged to continue exercising their skills and abilities in your program.
Jun 29, 2016
1,097 words in the original blog post.
Today we published the third episode of our podcast series ‘Big Bugs’ hosted by me, where I am joined by special guest Adam Hartway of Digital Safety (DiSa) to explore a $15K bug uncovered in their winner takes-all bug bounty program. DiSa is the global leader in Digital Protection for products in the retail channel, and they recently shipped out secured tablets to security researchers to test their strength against hackers. The results of this experiment are discussed on our podcast, along with additional resources for mobile and IoT security testing, as well as a call to continue the discussion on our forum.
Jun 27, 2016
193 words in the original blog post.
Putsi, a professional video game programmer turned information security specialist, has been actively involved in bug bounty programs for several years, with a significant presence on Bugcrowd, having recently entered the top 40 on the platform. Putsi's journey into security research began accidentally when they landed an internship position through their software engineering internship search, and they have since submitted over 100 bugs to Bugcrowd and various independent bounties. They focus on a range of vulnerabilities including RCE, privilege escalation, authentication bypass, and SQLi, and are motivated by the challenge and unpredictability of hacking, as well as the opportunity to learn new skills and contribute to making the internet a safer place. Putsi offers several tips for other bounty hunters, including the importance of continuous learning, persistence, and following the infosec community on social media platforms like Twitter and Reddit. They predict that bug bounties will become more popular in the future, potentially taking resources away from traditional penetration testing, as companies prioritize security and bugs become harder to find.
Jun 14, 2016
810 words in the original blog post.
OWASP has launched a bounty program for one of its projects, the Zed Attack Proxy (ZAP), to utilize crowdsourcing for security controls and improve the quality of their open source application security landscape. As an authority on appsec, OWASP faces challenges such as verifying the quality of their projects due to limited resources. The bounty program aims to alleviate this challenge by testing security control libraries, including ZAP, against various attacks. To implement the idea, OWASP turned to its community of volunteers and partnered with Bugcrowd, a service provider, to utilize their platform for quality assurance. This collaboration enhances the security research community and improves security controls for developers and companies using OWASP projects.
Jun 13, 2016
551 words in the original blog post.
Bugcrowd's second annual State of Bug Bounty Report highlights the evolving dynamics of the bug bounty market, including trends such as the spread of crowdsourcing into traditional sectors, increases in payout averages, and shifts in researcher demographics across the globe. The report also explores the rise of "super hunters" and validates the growth of distributed resourcing approaches like bug bounty programs as a means to create parity with adversaries. The report is a follow-up to Bugcrowd's first report and provides deeper insight into the early stages of the relationship between hackers and organizations, showcasing the increasing adoption of crowdsourced cybersecurity programs across various industries.
Jun 08, 2016
239 words in the original blog post.
Nikaiw is a skilled security researcher with a strong track record on Bugcrowd, having found over 30 valid vulnerabilities in under six months, including several P1's. Nikaiw got their start with technology at a young age, learning through trial and error and eventually applying this curiosity to security research and Capture-the-Flag (CTF) challenges. They have been actively participating in bug bounty work for about a year now, motivated by the desire to learn new techniques and expand their knowledge, as well as the opportunity to contribute to the security of companies' infrastructure. Nikaiw's approach emphasizes perseverance and persistence, suggesting that even initial failures can be valuable learning experiences. As Bugcrowd continues to grow in popularity, Nikaiw sees a bright future for bug bounties, where both companies and young security enthusiasts will benefit from this collaborative effort.
Jun 06, 2016
612 words in the original blog post.
Bugcrowd has announced its May 2016 Hall of Fame winners, recognizing top performers who earned significant points through last-minute submissions. The top winner, mert, received a $2,500 bonus for topping the leaderboard with 786 points. Other researchers who will receive bonuses include hydrantlabs and Harie_cool, although their exact point totals are not specified. To excel in Bugcrowd, submitting high-severity bugs that result in critical security impacts can lead to bigger rewards and faster invitations to private bounty programs.
Jun 03, 2016
219 words in the original blog post.