May 2017 Summaries
10 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
Bug bounty programs do not necessarily provide adequate coverage or same caliber of testing methodologies as penetration tests, but they offer the benefits of depth and breadth due to the large number of testers participating in a program. The pay-for-results model used in bug bounties encourages deeper and more focused testing, often yielding results that penetration tests missed. Continuous testing is also crucial for effective security assessment, especially with agile development processes. Engaging the crowd through a bug bounty program expands access to the skills of penetration testers, exposing code to their expertise at scale.
May 31, 2017
368 words in the original blog post.
The event focused on helping women get a "seat at the table" in technology firms, featuring female leaders from companies like Uber, LinkedIn, SurveyMonkey, and Nextdoor. The panel discussion covered topics such as work-life balance, finding an advocate, being open to feedback, and the role of luck in careers. Key takeaways included the importance of taking an active role in managing one's own career, being open to growth opportunities, and recognizing individual strengths. The discussion also highlighted the significance of building relationships with mentors and managers who can shape one's career path. Additionally, it emphasized the need to look for value alignment when searching for new career opportunities and to identify key stakeholders involved in the interview process.
May 23, 2017
977 words in the original blog post.
The latest update to the Crowdcontrol program reporting within the Insights dashboard provides actionable and educational metrics for bug bounty programs, offering a high-level view of performance, vulnerability trends, submission volume, program response time, bounty spend, and more. The new features allow users to track trends in submission volume, severity, and types, as well as filter results by target, technical severity, and vulnerability types. Additionally, the update provides metrics on program performance, bounty spending, and custom filtering options, enabling users to export data for further analysis or reporting.
May 15, 2017
349 words in the original blog post.
Bugcrowd is hosting an online conference for bug bounty hunters on July 15th, 2017, featuring presentations from experienced hunters and penetration testers. The goal of the event is to provide opportunities for researchers to learn and improve their skills, as well as network with peers. BugCrowd is now accepting proposals for talks or presentations, focusing on intermediate to advanced technical topics.
May 11, 2017
141 words in the original blog post.
Bug bounties are not free-for-all contests, but rather a way for organizations to tap into a diverse pool of skilled professionals, including penetration testers, security engineers, and software engineers, who provide testing talent at scale. The Bugcrowd community is comprised of 60% full-time professionals, and the platform offers invitation-only programs that narrow the testing pool based on skill level, expertise, or geography. To address concerns about trust and control, organizations can set parameters, utilize a partner, leverage historical data, and weigh risk vs. reward to maximize the benefits of bug bounties while minimizing potential risks.
May 10, 2017
696 words in the original blog post.
This week we have some exciting news related to our latest Vulnerability Rating Taxonomy (VRT) release! Our VRT is a dynamic resource outlining Bugcrowd's baseline priority rating for the vulnerabilities most often seen within the vulnerability assessment space. We've decided to partner with the security community at large to help provide a more diverse perspective and keep the VRT current and reflective of market needs by releasing it as an open source tool through GitHub. This will empower the community to take part in a full dialogue with our team and influence the way we shape and expand our taxonomy to address vulnerabilities beyond web applications. To submit a suggested change, one can go to github.com/bugcrowd/vulnerability-rating-taxonomy and provide detailed information around their suggestion, which will be valuable in shaping the VRT. Our latest version, VRT 1.1, introduces substantial revisions including additions to server security misconfigurations, XSS, and CSRF, some priority changes, and a few minor subtractions.
May 08, 2017
440 words in the original blog post.
Penetration testing involves hiring external consultants for time-boxed engagements to identify vulnerabilities, whereas bug bounties engage a large community of testers with diverse expertise and skills, providing continuous coverage and incentivizing researchers to find high-quality bugs. The key differences between the two models lie in their approach, scope, and results, with bug bounties offering advantages such as increased diversity, ongoing coverage, and higher payouts for severe vulnerabilities.
May 05, 2017
621 words in the original blog post.
Jet.com takes security seriously and has been running a successful bug bounty program for more than two years, rewarding 171 security vulnerabilities through its partnership with Bugcrowd. The company has increased rewards for mobile vulnerabilities to attract top security talent and encourage researchers to identify critical issues early. By adding a 25% incentive for mobile targets, Jet.com aims to create a competitive scope and reward model that benefits both the organization and the security research community. This approach is part of a broader trend in vulnerability pricing, where companies are initially launching private programs, taking them public, and increasing rewards to attract top talent and demonstrate their commitment to the security research community.
May 04, 2017
435 words in the original blog post.
Bugcrowd has announced its April 2017 Hall of Fame winners, with mongo taking first place, followed by darkieduck and yappare in second and third. To recognize their performance, the top researchers will receive bonuses for their work in April. High-severity bugs that pose significant security risks earn more points and can lead to faster invitations to private bounty programs. The May Hall of Fame results are eagerly anticipated.
May 03, 2017
217 words in the original blog post.
We are pleased to announce that two researchers have won a cash prize in our latest bug bounty program for reporting vulnerabilities against tough targets, including thick client applications such as Avira and AVG Technologies. The winners, Abr1k0s and an anonymous researcher, received $1000 and $500 respectively, contributing to a 100% increase in valid submissions reported across multiple programs and targets. Our crowd has shown impressive growth, with over 20 unique researchers participating and submitting vulnerabilities, resulting in significant rewards for those who have successfully identified security flaws. We congratulate all four winners this quarter and look forward to running more promotions in the future.
May 02, 2017
206 words in the original blog post.