February 2020 Summaries
5 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
The text discusses a Unicode vulnerability discovered by Wisdom in GitHub's password reset system. The vulnerability allows an attacker to trigger a password reset email to be delivered to the wrong email address due to incorrect handling of Unicode characters. A lab has been created for researchers to practice exploitation against this vulnerability, and it is essential to understand Unicode to identify and fix such issues. The vulnerability can be fixed by converting emails to ASCII or using the email address from the database instead of the user-provided one. This highlights the importance of understanding character encoding and its potential vulnerabilities in software.
Feb 28, 2020
876 words in the original blog post.
Bugcrowd is expanding its technology stack to integrate collective creativity anywhere within the security development lifecycle, aiming to balance human ingenuity and technological efficiency. The platform is introducing new features such as Skills Enrichment, Program Expansion, Unlocking the Enterprise, Workflow Your Way, Connect to More, and See More, Share More to improve the overall security coverage crisis faced by organizations. These enhancements are designed to provide more control for multiple programs and marketplaces, streamline workflows, and offer easy API creation for OEMs, as well as executive reports to communicate program value to stakeholders.
Feb 24, 2020
886 words in the original blog post.
Bugcrowd is planning its next LevelUp, a virtual infosec conference series featuring high-quality technical presentations by the community, with an extended call for proposals (CFP) now open until 14th March 2020. The event aims to showcase leaders in hacking and crowdsourced security, new testing techniques, best practices, strategies, and research to help bug hunters develop their skills. The CFP is open to any compelling presentations, but particularly seeks submissions on API & Mobile, Code Review, Recon techniques, New attacks, Testing methodologies, Soft career developing skills, with presentation lengths ranging from 20 to 50 minutes. Submissions can be made through the provided link and Bugcrowd's team will be happy to assist with questions. The event is expected to take place in May 2020.
Feb 21, 2020
264 words in the original blog post.
As Bugcrowd continues to invest in its researchers, it's partnering with PentesterLab to help them level up their skills. The online platform offers modules that allow users to learn at their own pace and includes video tutorials for more challenging topics. Bugcrowd is committed to helping its community members improve their skills, offering rewards for active hackers who participate on the platform.
Feb 11, 2020
215 words in the original blog post.
The company is announcing its 2020 Incentive Programs with several changes, including a shift in the start date for the year to February 1, 2020 through January 31, 2021. The incentive programs include the MVP program, which recognizes researchers who consistently bring their A-game across Bugcrowd's Bug Bounty and Vulnerability Disclosure Programs, and the Bounty Slayer program, which rewards high achievers with cash bonuses. The P1 Warrior program has also been updated to recognize those hackers who reach milestones of 150, 250, or 500 valid P1 submissions. Researchers can earn rewards by meeting specific criteria, such as maintaining a minimum average accuracy rate of 80% and submitting at least four qualifying submissions in a quarter.
Feb 04, 2020
586 words in the original blog post.