November 2017 Summaries
8 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
MacOS High Sierra contains a trivially-exploitable flaw that allows malicious individuals to generate persistent root access accounts, which can affect remotely accessible services such as Remote Desktop and Screen Sharing. To protect yourself, avoid testing this vulnerability on your own system and lock your computer when not in use, or take steps like changing the root password, blocking remote services, and reaching out to security teams if testing was done on a work MacBook. The vulnerability is not known to be remotely exploitable unless you have multiple accounts on your system, including guest accounts, and Remote Desktop is enabled. Apple has pushed a security update to address this issue, and users are encouraged to apply it as soon as possible.
Nov 28, 2017
613 words in the original blog post.
The bug bounty market is rapidly evolving, with many organizations embracing this concept despite some confusion surrounding paying hackers for vulnerabilities. A clear understanding of the distinction between bug bounty and extortion is essential, as a bug bounty is a reward offered for vulnerabilities discovered within a set scope, whereas extortion involves exploiting a vulnerability, selling information back to an organization, and then attempting to collect payment. The Uber breach, where a hacker exploited a vulnerability, was paid a ransom by Uber, which some argue is best practice, but others see as extortion. A bug bounty program should have clear guidelines, mutual respect between researchers and companies, and a trusted partner to help manage the relationship. Responsible disclosure programs shift the balance, removing uncertainty about what will happen when vulnerabilities are discovered, and having a trusted partner can create a competitive program that draws top researchers.
Nov 27, 2017
664 words in the original blog post.
The Bugcrowd Hacker community has grown by 71% since last year's report to over 65,000 members from more than 100 countries, with a wide range of technologies and expertise represented. The majority of bug hunters are young, determined individuals motivated by the challenge and eager to develop their skills. Many researchers hold regular jobs but aspire to become full-time bug hunters. Bug bounty programs have become more complex, requiring careful consideration of variables such as scope, program type, reward ranges, and public disclosure policy. Bugcrowd's Researcher Success team helps ensure a high-quality community by building relationships, providing tools and education, and managing incidents, ultimately creating a happy and engaged hacker community.
Nov 21, 2017
594 words in the original blog post.
We are excited to introduce new submission search and filtering capabilities to Crowdcontrol, built to optimize the time you spend finding submissions. Our recent data shows a steady rise in vulnerability submissions, with a 67% increase year over year, driven by bounty adoption growth and larger organizations with more attack surfaces. To help users keep up with this increase, we've introduced novel search capabilities, including tokenized search, intuitive search bars, preset filters, and keyword search functionality. These features aim to simplify the process of finding relevant submissions, providing a seamless experience for researchers and customers alike.
Nov 21, 2017
571 words in the original blog post.
The Inside the Mind of a Hacker 2.0 report provides insights into the profiles and stories of security researchers, highlighting their unique characteristics, motivations, and strengths. The Bugcrowd community has grown to over 65,000 members, contributing significantly to organizations' defenses by identifying vulnerabilities at high speeds. A successful bounty program relies on building strong relationships with the researcher community, engaging them through a well-designed program, and providing intrinsic and extrinsic rewards. The report aims to help customers understand the various motivators of researchers and best engage with their needs. Additionally, two profile interviews with top Bugcrowd researchers are available, offering insights into what drives these experts to contribute to the community.
Nov 14, 2017
392 words in the original blog post.
We are consistently asked “How Do I Earn Private Program Invitations?”
Since 2015, we have used performance and activity markers to choose program participants. The criteria include Quality, Impact, Activity, (+1 to Skills), and Trust. For a private program invitation, researchers must meet the following guidelines: Consistently submit valid findings (at least 50% in the last 90 days) with an average submission priority score between 1.0 and 3.99; actively submit bugs in the last 90 days; demonstrate specific skills; and maintain trust by staying within the scope of bounty briefs. To maximize potential, researchers should carefully review each bounty brief, validate findings before submitting, and consider submitting critical issues to level up their skills.
Nov 10, 2017
518 words in the original blog post.
IDOR (Identity-Based Data Exposure) vulnerabilities are a significant threat in web and mobile applications, offering higher impact and paying potential than other types of bugs. An IDOR vulnerability occurs when an attacker can access, edit or delete another user's objects by changing the values of variables such as "id", "pid", and "uid". Understanding application flows, identifying injection points, and using tools like Burp Suite are essential for finding and exploiting these vulnerabilities. Blind IDOR cases can be particularly challenging to detect, but combining them with other vulnerabilities can increase their impact. Critical IDORs pose a significant risk in areas such as password reset and account recovery, while HPP (HTTP Parameter Pollution) testing can help identify vulnerabilities. To prevent IDOR vulnerabilities, it's crucial to control API requests, provide permissions for endpoints, and use hash functions to make attackers' jobs harder. By understanding the impact of IDOR vulnerabilities and taking proactive measures, developers can significantly reduce their occurrence.
Nov 09, 2017
2,220 words in the original blog post.
Congratulations are in order as Bugcrowd recognizes its top performers from October 2017, with todayisnew taking first place and noob and a private user rounding out the top three. These researchers earned significant bonuses for their outstanding work, which includes identifying high-severity bugs that pose critical security risks such as remote code execution or elevation of privilege. To excel in this field, one must be able to identify and submit high-quality bug reports, with those who do so earning substantial rewards and potentially even invitations to private bounty programs. Bugcrowd is grateful for the hard work of its researchers and looks forward to announcing the November Hall of Fame winners.
Nov 01, 2017
198 words in the original blog post.