August 2016 Summaries
5 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
Cross-Site Scripting (XSS) has become a persistent threat in software security, appearing consistently in top vulnerability lists and being submitted through bug bounty programs. However, not all XSS vulnerabilities are equal, and the increasing phenomenon of XSS-Fatigue suggests that defenders are becoming more adept at mitigating these issues. This episode of Big Bugs delves into high-impact XSS bugs found in the wild, explores resources for defenders and offenders alike, including browser exploitation frameworks, bug bounty programs, and expert tools like BeEF and Polyglots. To further aid understanding, it also provides a comprehensive overview of XSS research, including multi-context polyglot payloads and filter bypass techniques.
Aug 30, 2016
226 words in the original blog post.
The presentation by Jake Kouns and Christine Gadsby at Black Hat 2016 emphasizes the importance of managing Open Source Software (OSS) security within organizations, highlighting the risks and benefits associated with its use. The authors suggest a maturity model with five levels, ranging from Level 1, where no resources are spent on OSS security but it's highly risky, to Level 5, where OSS security is fully optimized and integrated into the organization's processes. This approach encourages a proactive and collaborative relationship between developers and security teams, leveraging bug bounties and responsible disclosure policies to improve product security.
Aug 30, 2016
618 words in the original blog post.
Mobile penetration testing involves breaking down into three components: client-side, traffic/network, and server-side. The network and server-side vulnerabilities are largely similar to web application testing, with APIs being a key difference. Client-side vulnerabilities typically require physical device access and have security controls in place, making them less accessible. Setting up an Android device for mobile testing involves configuring Burp Suite, setting the device's proxy settings, and installing the certificate, which can be done by following specific steps to ensure that traffic is proxied through the computer. The process of setting up the device allows researchers to start hacking on mobile bug bounties and participate in a raffle for cash prizes.
Aug 25, 2016
1,517 words in the original blog post.
Bugcrowd has announced its July 2016 Hall of Fame winners, with mert topping the leaderboard with 513 points and receiving a $2,500 bonus. VINOTHKUMAR came in second with 462 points earning him a $1,500 bonus, while krbtgt rounded out the top three with 300 points securing a $1,000 bonus. The company recognizes that high-severity bugs can significantly impact security, offering more kudos points for these types of submissions. Bugcrowd researchers who submit high-severity bugs may be eligible for private bounty programs and potentially receive invitations to participate in these exclusive programs.
Aug 10, 2016
247 words in the original blog post.
We spent the week in Las Vegas attending conferences and events related to information security, including Black Hat and DEFCON. We caught some great talks from industry experts such as Dan Kaminsky, Jason Haddix, Leif Dreizler, Kymberlee Price, Jake Kouns, Christine Gadsby, Wendy Everette, Josh Corman, Luke Young, and many others who presented on various topics including security research, incident response, product liability law, automotive cybersecurity, and more. We also attended sponsored events such as happy hours, parties, and a CTF in the DEFCON Car Hacking Village, which provided opportunities to connect with the security community and learn from experts like Fitbit and Okta. Our company engaged in partnerships with organizations like (ISC)2 and hosted several meet and greets with attendees, including a kick-ass experiential event. We also showcased our new subdomain discovery tool Enumall and provided resources for attendees interested in improving their product incident response programs.
Aug 09, 2016
638 words in the original blog post.