July 2016 Summaries
5 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
This week's Big Bugs podcast delves into the world of mobile hacking, gaming, and security, focusing on Pokémon Go and its technical issues. The episode reviews some of the game's problems, including a DDoS attack by a group called "PoodleCorp" and an incident where users had to provide full access to their Google accounts. The podcast also explores how hackers have reverse-engineered the game, uncovering details about its code, Unity framework, and Protobuf protocol used for communication between the client and server. Additionally, it discusses third-party development, botting, and patched clients, as well as tips and tricks for catching Pokémon. The episode concludes by discussing future plans for securing Pokémon Go and provides valuable insights into the game's mechanics, including its evolution system, capture rates, and legendary Pokémon.
Jul 29, 2016
1,428 words in the original blog post.
Crowdcontrol's new "Insights" dashboard provides a visual way to understand engagement over time, trends in submissions and action items for teams involved in bug bounty programs. The dashboard offers insights into four program metrics: Submissions Over Time, Priority Per Submission, Bug Types, and Status of Bugs. These metrics help program owners monitor submission activity, prioritize critical vulnerabilities, identify common weaknesses, track the status of submissions, and make data-driven decisions to improve their program's performance and effectiveness.
Jul 28, 2016
386 words in the original blog post.
In April we announced a Mobile bonus reward program for researchers that submitted valid, non-duplicate mobile vulnerabilities for a chance to win $1000, and in early June we expanded the program to two bonuses. We are excited to announce our two winners, and congratulate putsi and robinooklay for their mobile submissions! The program has been extended with new rules, now from July 1st through September 30th, every valid and non-duplicate mobile vulnerability submitted will be entered into a raffle to win one of two cash prizes. Each valid submission equals an additional entry into the contest, so submitting multiple valid bugs increases chances to win. Researchers can get started by emailing [email protected] with their interest in mobile app testing and specifying the physical hardware they have access to test on. Bugcrowd also offers public programs for testing, including various companies' mobile apps, and a resource kit for mobile testers and developers.
Jul 18, 2016
331 words in the original blog post.
Fiat Chrysler Automobiles has launched a public bug bounty program to improve the security of its connected vehicles, following in the footsteps of other companies like Tesla and Western Union, which have already adopted similar initiatives. The company is leveraging Bugcrowd's platform to tap into the collective creativity of over 30,000 security researchers worldwide. With a focus on Fiat Chrysler's connected vehicles, including external services and applications, the program aims to encourage independent security researchers to report vulnerabilities and help fix them before they become issues for consumers. The rewards scope ranges from $150 to $1,500, with explicit permission required to disclose results of submissions. This move marks an important step forward in automotive security, as Fiat Chrysler prioritizes the safety of its customers and acknowledges that hackers are already present and willing to collaborate.
Jul 13, 2016
418 words in the original blog post.
Bugcrowd has announced its June 2016 Hall of Fame winners, with mongo topping the leaderboard due to his exceptional work across the platform. The top three researchers are mongo, mert, and Web_Plus, who will receive bonuses for their performance. High-severity bugs that result in critical security impact earn the most points, and submitting these types of bugs can help researchers get invited to private bounty programs faster. Bugcrowd is excited to recognize its top performers and looks forward to announcing the July Hall of Fame results.
Jul 11, 2016
253 words in the original blog post.