Home / Companies / Bugcrowd / Blog / February 2017

February 2017 Summaries

18 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
The bug bounty market continues to grow, with researchers using their experience to build and grow successful careers in penetration testing or bug hunting. Successful hunters have parlayed their skills into security jobs at major companies by conducting themselves professionally, sharing their techniques publicly, building relationships with program owners, citing their experience on resumes, and networking with fellow researchers. The security community is global and interconnected, making it easy to meet fellow researchers through Twitter lists, IRC channels, Reddit forums, security conferences, and local meetups, which can lead to job opportunities and growth in the industry.
Feb 28, 2017 505 words in the original blog post.
The 2017 CISO Investment Blueprint analyzes survey responses from 100 security decision makers regarding the current state of application security. The blueprint also features interviews with innovators in the security industry, including Dave Farrow, Barracuda's Senior Director, Information Security, who discusses his team's challenges and successes in addressing application security issues. Farrow highlights the importance of transforming developers into security professionals and filling systemic gaps in their understanding through training programs. He also emphasizes the value of bug bounty programs in providing access to top appsec professionals and immediate results. The blueprint aims to provide insights around the challenges and opportunities present for security decision-makers in 2017, and invites feedback and observations from readers.
Feb 24, 2017 1,083 words in the original blog post.
A vulnerability was disclosed by Google's Project Zero in Cloudflare's CDN and DDoS prevention service, specifically affecting HTML parser for certain features. This resulted in sensitive information leaking of other Cloudflare customers. Bugcrowd, a security platform, was not directly affected but has invalidated all sessions as a precautionary measure. Users of the Bugcrowd API are advised to rotate their credentials and change their password due to potential risks. The company thanks users for their understanding and offers support if needed.
Feb 24, 2017 143 words in the original blog post.
The Hackathon wrapped up with impressive projects showcasing creativity and problem-solving skills. The event saw high participation from team members, who worked on multiple projects and shared their goals of making "small impacts" across various initiatives. The diversity in projects was notable, ranging from business-critical to innovative ideas such as a voice-enabled mannequin. The event highlighted the company's emphasis on security, with participants addressing security considerations upfront despite not having security backgrounds. The release of the bi-directional Bugcrowd API also received positive feedback and sparked further exploration and development. The outcome was seen as an excellent opportunity for team members to work together and solve interesting problems in innovative ways, setting a promising stage for future quarterly Hackathons.
Feb 23, 2017 420 words in the original blog post.
This post discusses the importance of writing successful bug submissions, highlighting three key ideas: thoroughness, simplicity, and neutrality. Thoroughness is crucial to ensure that the bug can be reproduced by others, while simplicity helps to avoid unnecessary complexity in the report. Neutrality is vital to convey the impact of the bug without bias or exaggeration. Furthermore, courtesy towards the person receiving the report, who may have other responsibilities and challenges, is essential to build trust and potentially increase bounty amounts. By following these four principles, individuals can improve their bug reports and enhance their bug hunting experience.
Feb 22, 2017 941 words in the original blog post.
Our January winner, taDXtLD, received a $500 bonus for submitting a valid bug against a thick client target. To participate in the promotion, review our list of programs and test against them, then submit any found bugs until March 31st, 2017. For those new to thick client software hacking, we've compiled go-to resources like "Hacking – the Art of Exploitation" or the Embedded Security CTF to help multiply their skills. The promotion is open to all valid submissions against thick client targets. Bugcrowd's Application Security Engineering team is happy to provide additional support with any questions.
Feb 21, 2017 188 words in the original blog post.
The RSA Conference featured a kickoff dinner for CISOs and guests, where attendees discussed crisis communications, organizational communication strategies, and security through visibility. The conference also included sessions on building an application security program, integrating with Qualys, securing customer data, DevOps, Slack security, IT security training programs, the "cyber-circus" of hacking everyday things, and the intersection of appsec and SDLC. A party was held at the Old SF Mint, which had a great turnout, and Bugcrowd also participated in Passcode's Bug Bounty Lightning Talks event with one of their top researchers.
Feb 17, 2017 434 words in the original blog post.
Intercom has launched a public bug bounty program to improve the security of its customer messaging platform and protect customer data. The program aims to implement a secure development lifecycle and issue monetary rewards of up to $1,500 per identified vulnerability depending on impact and severity. Intercom believes that this program is essential in addressing the latest cybersecurity challenges and relies on customer trust to keep its customers' data secure. The company has expanded its private bug bounty program with Bugcrowd to tap into a bigger pool of security researchers and improve its ability to find and fix vulnerabilities.
Feb 16, 2017 188 words in the original blog post.
The 2017 CISO Investment Blueprint was launched, analyzing survey responses from 100 security decision makers regarding the current state of application security. The blueprint also includes insights from industry innovators and will be followed by the publication of interviews with security experts, including Brad Arkin, Vice President and Chief Security Officer at Adobe. In his interview, Brad discusses his background in software security, his accomplishments in 2016, such as implementing the Common Controls Framework, and challenges he faces in consolidating disparate teams and processes. He also shares his thoughts on improving appsec, including the importance of containerization and certifications, and the effectiveness of bug bounties. Brad's goals for 2017 include continuing to work on certifications, data sovereignty, platform security, and collaboration automation. The blueprint is available for download, and feedback is encouraged through social media or email.
Feb 16, 2017 926 words in the original blog post.
This article discusses the importance of note-taking and session tracking for bug bounty hunters, with tools like Keepnote, Microsoft Onenote, Notepad++, and Sublime text being recommended for note-taking, and tcpdump and Wireshark being used for packet tracking. The author also highlights the use of Burp Suite Pro for web application testing, which allows saving sessions and storing traffic in project files. Additionally, the article touches on using scripting tools like `script` to log terminal commands and automate tasks, making it easier to demonstrate steps taken during a bug hunt or pentesting engagement.
Feb 14, 2017 1,257 words in the original blog post.
Bugcrowd has partnered with Qualys, allowing their joint customers to share vulnerability data between the two platforms. This integration combines automated scanning capabilities with the power of the crowd to reduce the cost and effort of managing vulnerabilities across an organization. The partnership will enable Bugcrowd's customers to import Qualys Vulnerability Assessment (WAS) scan results into a designated program on Bugcrowd's platform, facilitating faster communication between researchers and improving the overall experience for both parties. On the other hand, Qualys users will be able to import vulnerabilities discovered by Bugcrowd into the WAS interface, allowing them to manage these vulnerabilities and move them through their workflow more efficiently, ultimately decreasing time to resolution.
Feb 13, 2017 246 words in the original blog post.
The 2017 CISO Investment Blueprint analyzes survey responses from security decision makers on the current state of application security. The blueprint also features interviews with industry innovators, including Richard Rushing, CISO at Motorola Mobility, who shares his insights on appsec challenges and opportunities in 2017. Rushing discusses his background in security, moving from offense to defense, and his experience working with companies to implement secure coding practices, APIs, and flexible programming. He emphasizes the importance of awareness and early implementation of security measures in development processes. The blueprint is available for download, and readers are encouraged to share their thoughts and feedback on appsec challenges and opportunities in 2017.
Feb 09, 2017 926 words in the original blog post.
This is an introduction to the second post in a series on "Bug Bounty Hunter Methodology". Understanding the scope and rules of a bounty program is crucial for eligibility and reward purposes. The scope outlines what type of security vulnerabilities are accepted, where testing is allowed, and what types of testing are permitted. Disclosure terms and rules describe how to report bugs and outline disclosure policies for programs. Targets list applications and services that can be hacked on, while out-of-scope sections exclude specific types of security findings and bugs. Going out of scope without permission risks no reward and a negative reputation. The bounty brief includes rewards information, testing details, and other useful information for researchers.
Feb 08, 2017 543 words in the original blog post.
The latest release of Bugcrowd's Crowdcontrol platform has been made available, offering several cutting-edge features designed to streamline bug bounty management for organizations. The new release focuses on integrative workflow, insightful reporting, and researcher enablement, aiming to simplify integration, deliver a unified security status view, and improve the experience for both customers and researchers. A bi-directional API allows seamless data exchange, custom fields enable alignment with existing workflows, and role-based access partitions team roles between programs. The On-Demand program report provides valuable quantitative data and meets compliance needs, while researcher enablement features include an updated submission form and a new payout method through Payoneer.
Feb 07, 2017 449 words in the original blog post.
Today, as I embark on a new journey with Bugcrowd, I reflect on the most common question I have heard: “why leave Okta?” It’s a good question. I am honored to have served as the Chief Security Officer at Okta, building a world-class security program for a truly innovative company. Moreover, the ride at Okta was meteoric and I know they will continue on their path to success. But now, it’s time for disruption. To be more specific, the opportunity to completely change the information security industry. That is where Bugcrowd is going – and that train is leaving the station with me on it. The company has perfected its bug bounty market delivery, proven by Federal Agencies pushing programs, indicating a growing market. I am thrilled to see this growth, as it extends beyond just bug bounty programs. Implementing a gig economy model can change the face of security for everyone, addressing a significant talent deficit in the industry. As Vice President of Operations, I will help foster connections between customers and the crowd, aiming to fundamentally change how security is done.
Feb 07, 2017 461 words in the original blog post.
Bugcrowd has announced its January 2017 Hall of Fame winners, recognizing top performers such as mongo, satishb3, and zseano for their exceptional work. These researchers have earned significant rewards, including bonuses ranging from $1,000 to $2,500, in recognition of their contributions. To excel on Bugcrowd, high-severity bugs that pose a critical security risk are highly valued, as they not only offer substantial kudos points but also increase the chances of being invited to private bounty programs. The winners' achievements demonstrate the importance of Bugcrowd's platform in fostering a community of skilled researchers who drive bug discovery and reward innovation.
Feb 06, 2017 218 words in the original blog post.
This week, Plushcap launched its 2017 CISO Investment Blueprint, which analyzes survey responses from 100 security decision makers on the current state of application security. The blueprint also features interviews with innovators in the security industry, including Kim Green, CISO at Zephyr Health and founder of KAZO Security. Kim shares her insights on appsec challenges and opportunities, highlighting issues such as third-party APIs and microservices, and emphasizes the need for cloud service providers to enhance their security offerings. She also discusses the importance of bug bounty programs, which she sees evolving with "advanced crowdsourcing" technology. The blueprint aims to provide guidance for security decision-makers in 2017, and Plushcap invites feedback and insights from readers.
Feb 03, 2017 752 words in the original blog post.
This post from Bugcrowd introduces their "Bug Bounty Hunter Methodology" series, which will provide resources and information to help aspiring security researchers or bug bounty hunters get started. The company works with companies to create crowdsourced security tests through public and private bug bounty programs or responsible disclosure programs, rewarding researchers for finding valid security vulnerabilities. To start, it's recommended to focus on a specific area of hacking that interests you and learn from there, as mastering everything at once is not necessary. The first version of the methodology focuses on web application testing, which is a common target for bounties. Bugcrowd has identified two must-read resources: "The Web Application Hacker’s Handbook" and OWASP WebGoat, both of which are essential for learning web application hacking and penetration testing. Other recommended resources include tools such as Burp Suite, OWASP Zap, and Kali Linux, which can help make the hacking process easier.
Feb 02, 2017 612 words in the original blog post.