November 2018 Summaries
17 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
In recent weeks, hackers have successfully exploited vulnerabilities in widely used software and services, including a JavaScript library to steal bitcoin, a US Postal Service API that exposed over 60 million users' data, and Small Office and Home Office (SOHO) routers, which are now being standardized for security. The German government has published draft rules to secure SOHO routers after a 2016 incident where nearly a million routers were hijacked. In the US, prosecutors have indicted eight individuals from Russia, Ukraine, and Kazakhstan for running a cybercrime network that falsified billions of website visits. Additionally, Marriott's Starwood reservations database was breached, resulting in the theft of 500 million guests' personal information. Experts emphasize the importance of practicing deep security testing, using password managers, and implementing best practices to prevent similar breaches.
Nov 30, 2018
655 words in the original blog post.
The Marriott breach is notable for the large amount of personally identifiable information (PII) stolen, including passport numbers, which increases the risk of identity fraud. The breach was discovered nearly three months after it occurred, highlighting the challenges in detecting such incidents. The impact of this breach will be significant due to the demographics of those affected, many of whom are likely hotel reward members who have not implemented robust password management strategies. To protect oneself, it is recommended to sign up for credit monitoring, use a password manager, activate two-factor authentication, and minimize password reuse. Given the potential for the stolen data to be exploited by cyber attackers, it is essential to review one's personal security posture and take proactive measures to mitigate the risk of identity theft.
Nov 30, 2018
527 words in the original blog post.
Moving Security out from Under the Hood` highlights the challenge in framing security as a product or service differentiator, where consumers are not as clear in their needs as they are with other features. To shift this, Bugcrowd's Casey Ellis and Prevalian's Liz Wharton emphasize four key elements: data-driven research, economization of scalable solutions, legislative best practices, and socializing security concepts in a consumer-friendly language. The crowdsourced security model has helped organizations find vulnerabilities faster and more efficiently, with increased adoption and reported returns spurring legislative support. Socialization is critical for mainstream adoption, as consumers may struggle to assign value to one approach over another. By seeding value at the customer level, initiatives like Keren Elezari's TedTalk have elevated crowdsourced security programs' importance amongst mainstream buyers. The virtuous cycle of growth and value multiplication has been observed in both hackers and program customers, where increased adoption leads to more unique skills surfacing, and a focus on excellence promotes quality at scale. Ultimately, the driving force behind revolutionary security methodologies like crowdsourced security lies in the conversation around why this technology is necessary today, and what it means for every consumer.
Nov 28, 2018
785 words in the original blog post.
Open source is a powerful tool that has significantly accelerated technology advancements over the last 20 years, with almost every organization using open source code. However, this also brings security risks due to the vulnerability of the supply chain and the fact that many libraries are maintained by unpaid teams in their spare time. A recent attack on a widely used node.js module highlighted the potential for compromise when the inherent vulnerability of the supply-chain gets exploited. The attacker took advantage of the trust built through contributing to the library, befriending the maintainer, and eventually merging malicious code into the master codebase. To prevent such incidents, deep and continuous security testing is essential, as simply securing one's own code does not guarantee the safety of the code others write for it. The power of the crowd can also be leveraged to identify impact and severity through online discussions and reverse-engineering efforts.
Nov 27, 2018
564 words in the original blog post.
Bugcrowd is excited to announce its October 2018 Hall of Fame winners, but first, the company acknowledges a technical issue with its leaderboards that are displaying incorrect total points for some Researchers. The company is actively investigating and resolving this issue and thanks its Researchers for their continued partnership. Bugcrowd recognizes top performers in various paid programs by awarding bonuses ranging from $1,000 to $3,000, which the company values as a result of their hard work. The company encourages Researchers to submit high-severity bugs that can help them earn bigger rewards and get invited to private bounty programs faster. Finally, Bugcrowd expresses its gratitude to all its Researchers for their contributions and looks forward to announcing its November Hall of Fame results.
Nov 20, 2018
322 words in the original blog post.
Phillip Wylie, a Bugcrowd Ambassador in Texas, USA, has been sharing his knowledge and experience with the security community through various initiatives. He is passionate about teaching and mentoring others, which led him to create the Pwn School Project, providing free pen testing education to his community in Dallas, Texas. Phillip has been working in the industry for over 15 years, starting as a sysadmin and moving into network and application security before becoming a pentester. He advises beginners to learn the underlying technologies of systems, networks, applications, and hardware before diving into hacking. Phillip's favorite pentesting tools include Burp Suite, SQLmap, nmap, and Nikto, which he uses for web app pen testing, vulnerability scanning, and discovery. He emphasizes the importance of manual hacking techniques and suggests that bug bounty hunters learn unique techniques to enhance their skills. Bug bounties have impacted his life by teaching him new skills and introducing him to unique techniques. In his free time, Phillip enjoys spending time with family and friends, watching movies, and attending security meetings.
Nov 19, 2018
557 words in the original blog post.
Russia's apparent lack of involvement in the US midterm elections has raised questions about why they didn't get involved, despite unleashing cyberattacks and disinformation during the 2016 presidential election. A brief disruption to Google traffic was reported, which could have been caused by a technical error or a malicious attack, but Google said its services were not compromised. Meanwhile, a cross-site request forgery vulnerability in Facebook exposed user data, prompting predictions of more sophisticated social engineering attacks in the future. Cybersecurity breaches continue to be a concern, with recent incidents at Nordstrom and potential government contractor breaches on the horizon. The US is moving forward with a new cybersecurity initiative called the "Moonshot," which aims to make the country a global leader on cyber security over the next decade. This effort comes after warnings from the National Security Telecommunications Advisory Committee that cyber threats pose an existential threat to American life. A proposed rule by the General Services Administration will require government contractors to disclose breaches in order to provide better visibility into government contract security.
Nov 16, 2018
524 words in the original blog post.
When a security researcher discovers a bug in software, informing the company is the responsible thing to do, allowing them to fix it. Pinterest has an ongoing program with Bugcrowd to manage reports of valid bugs and provides monetary rewards to researchers who submit them. The program has been successful, rewarding over $35,000 to more than 150 non-duplicate submissions, and recently increased rewards for all tiers of bugs to show continued commitment to responsible disclosure. Researchers can participate in the program by reading the brief and terms on Bugcrowd and joining Pinterest's effort.
Nov 15, 2018
248 words in the original blog post.
Bugcrowd has announced its Next Gen Pen Test, a new product designed to meet the changing security needs of today's enterprise. According to a recent survey of 200 security leaders, many are dissatisfied with their current pen test efforts due to limited coverage and inability to integrate results into software development lifecycle. The traditional model is constrained by limited resources and time, resulting in organizations spending millions of dollars on pen tests without seeing value. Next Gen Pen Test offers continuous coverage, proven pen testers and whitehat hackers, and SDL integrations, disrupting the current market with a scalable model that delivers compound value across the business.
Nov 14, 2018
451 words in the original blog post.
The Verizon Data Breach Investigations Report (DBIR) 2017 found that around 90% of breaches occur due to phishing, which is aided by successful email spoofing. Companies allowing spoofed emails from their domain are more likely to fall victim to phishing attacks. The release of VRT 1.6 includes changes to internal SSRF and how email spoofing is rated, with a focus on the baselines around SPF and DMARC. Major email providers have moved away from the SPF standard and now rely on DMARC, making it essential for companies to set up DMARC on their email domains to prevent spoofed emails from landing in inboxes. The VRT has updated its classification levels for email spoofing to P3/P4 and P5, reflecting the growing concern around this issue and encouraging companies to take action to protect themselves.
Nov 13, 2018
583 words in the original blog post.
Movember, a non-profit organization that raises awareness and funds for men's health, partnered with Bugcrowd to conduct its Next Gen Pen Test in early Fall. This collaboration aimed to improve the security of Movember's platform ahead of the month of November, when it experiences a significant influx of traffic. With Bugcrowd's Elite Crowd, Movember was able to identify and patch issues faster, while also facilitating communication between researchers and the foundation's small security team. The partnership provided actionable results, methodology, and reporting that met the foundation's audit and compliance requirements. According to Bugcrowd, its Next Gen Pen Test model delivers a scalable solution that overcomes limitations of traditional pen test models, enabling organizations to create compound value across their business while reducing operational and financial pitfalls.
Nov 09, 2018
493 words in the original blog post.
This week's election security news highlighted the growing threat of internal threats, as watchdog groups and online researchers warned about Americans using social media to suppress turnout or spread false rumors on Facebook and Twitter. The focus also shifted to vulnerabilities in voting systems, with a Georgia voter registration system being identified as insecure due to its ease of access for hackers. Additionally, an election security expert discovered a reference manual listing critical usernames and passwords for a voting machine vendor's tabulation system, which were easily crackable. Home routers have also been targeted via a Universal Plug and Play vulnerability, while the Bank of England planned a cyber attack exercise to test the financial sector's resilience. As more companies adopt stronger security stances, it is hoped that this will lead to a more secure internet in the future.
Nov 09, 2018
503 words in the original blog post.
The bug bounty industry has grown significantly over the past six years, with more hackers and organizations joining the community, presenting new challenges. Bugcrowd aims to increase transparency by explaining several issues and topics affecting the community. The company is improving its private invite system for researchers, adding a skill system to connect them with relevant programs, and addressing concerns about kudos programs. Leaderboards have been updated to focus on bug priority rather than kudos points, and the researcher platform is being improved with enhanced transparency and faster bug rewards. Additionally, Bugcrowd plans to increase swag giveaways and opportunities for researchers to earn recognition. The company values a diverse researcher community and aims to address feedback from the community through various channels.
Nov 08, 2018
1,315 words in the original blog post.
The gaming industry's focus on getting games out on time often leads to a lack of attention to security, making it an attractive target for hackers. However, some major game publishers, such as Valve, EA, and Blizzard, prioritize security with dedicated teams and procedures in place. The podcast highlights the opportunities for skilled gamers to become bug hunters and learn about improving game security.
Nov 07, 2018
248 words in the original blog post.
Traditional penetration testing has become a common practice for vulnerability assessment, but its effectiveness is often questioned due to various shortcomings. The drive to reduce costs through software automation and "check-the-box" compliance has led to a decrease in the efficacy of traditional pentests. Many organizations spend millions on compulsory pen tests without seeing any value in reducing actual risk, with security leaders expressing dissatisfaction with their current effort. Common challenges include blind spots due to consultants' billable hours and inflexibility, platform integrations that add operational overhead, and time-to-market issues that leave new application code untested for months. However, Bugcrowd's Next Gen Pen Testing (NGPT) offers a scalable model to sidestep these limitations, delivering 7x more vulnerabilities than traditional penetration testing and improving both security posture and software development best practices.
Nov 05, 2018
486 words in the original blog post.
This weekend's news that Georgia's voter registration system has been likened to an open bank safe door paints a bleak picture of the state of election security as we enter the midterm's final day. A series of security vulnerabilities have been discovered that would allow even a low-skilled hacker to compromise the system and potentially affect the election itself. The fact that it took only five security professionals a trivial amount of time to identify these vulnerabilities highlights the need for improved cybersecurity efforts, particularly in government institutions. However, the lack of accountability and lax approach to cybersecurity from some states is alarming, with laws that would have criminalized routine security research being vetoed by governors. This raises concerns about the effectiveness of current measures to protect election systems and underscores the importance of making one's voice heard to effect change.
Nov 05, 2018
374 words in the original blog post.
A webinar was recently hosted by InVision, featuring Johnathan Hunt and David Baker discussing the importance of expert program management in crowdsourced security. A managed bug bounty program can provide significant benefits over a self-managed one, including increased efficiency, cost-effectiveness, and reduced time and effort required for triage and validation. With a managed program, organizations can attract a solid crowd of researchers, establish attractive payout ranges, and determine logistics for payouts and researcher communications. InVision's transition from an unmanaged to a managed bug bounty program with Bugcrowd has resulted in an 80% reduction in required time and effort, allowing their application security team to focus on fixing vulnerabilities rather than managing the program. A crowdsourced security approach can provide a more complete security assessment at a lower cost per hour compared to other options.
Nov 01, 2018
664 words in the original blog post.