Earlier quoted context omitted.
This is hyperbolic nonsense. Having worked at AWS, I've never encountered a business that is more serious about their security position.
It's not, I still have the email exchange from a couple years back - I thought of posting it somewhere because it was so odd, but I dont have a blog and I am not interested in publicity. Amazon still doesn't offer a bug bounty program to my knowledge. Also, it's the only cloud provider my active security researcher friends tell me that attempts to regulate them by some weird pen test authorization requirements which…
Teen Becomes First Hacker to Earn $1M Through Bug Bounties
111–120 of 178 posts
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#112Earlier quoted context omitted.
It's not, I still have the email exchange from a couple years back - I thought of posting it somewhere because it was so odd, but I dont have a blog and I am not interested in publicity. Amazon still doesn't offer a bug bounty program to my knowledge. Also, it's the only cloud provider my active security researcher friends tell me that attempts to regulate them by some weird pen test authorization requirements which…
> pen test authorization requirements Yes, we don't want people to publicize when we fuck up so we'd rather just NDA them to death when they tell us about bugs. Edit: If you don't accept, we just use the hacking laws in the US to silence you.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#113Pro tip if you are a startup and want free security advice. Just sign up for all the bounty sites and for every single bounty just tell the submitter that it is a duplicate bug and pay them nothing, then hot patch it immediately and when they get suspicious tell them that their bug report had absolutely nothing to do with the timing of your patch. I know there are companies that do this because I have had it happen t…
Sounds like an actual use case for staking - bug bounties on teh blockchain!
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#114Pro tip if you are a startup and want free security advice. Just sign up for all the bounty sites and for every single bounty just tell the submitter that it is a duplicate bug and pay them nothing, then hot patch it immediately and when they get suspicious tell them that their bug report had absolutely nothing to do with the timing of your patch. I know there are companies that do this because I have had it happen t…
There is actually a very simple solution to this: publish a Merkel tree of submitted bug reports.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#115Earlier quoted context omitted.
Can you elaborate on the automated reports a bit more? What makes them uninteresting?
Examples of "vulnerability" reports I've received: - Dump of CVEs for "Web App X" or "Server X", even though literally zero of them apply to the version that I'm currently running. - Dumps of port scans with warnings like "Running SSH on port 22 is not recommended" and "Server accepts HTTP. Always use HTTPS". I assume there are tools that generate these reports because the reports use decent English but the accompany…
I'm having a hard time imagining a scenario where I manage a web server that is accessible to anonymous people running pen scanners on it that has a justifiable reason for broadcasting port 80.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#116Earlier quoted context omitted.
In my experience, security has much fewer of those resources. Most of the information seems to shared through word-of-mouth, conference presentations, and blog posts.
Much of the information is also just RTFM. I don't think it's a stretch to say that security is a lifestyle: if I read the documentation of an API, more often than not I'll wonder if something can be abused for something. Or when trying to register for health insurance, the password field required special characters, so I set my password generator to include them, after which the form broke, and so I investigated and…
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#117Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#118Earlier quoted context omitted.
Examples of "vulnerability" reports I've received: - Dump of CVEs for "Web App X" or "Server X", even though literally zero of them apply to the version that I'm currently running. - Dumps of port scans with warnings like "Running SSH on port 22 is not recommended" and "Server accepts HTTP. Always use HTTPS". I assume there are tools that generate these reports because the reports use decent English but the accompany…
What's the justification for running a host that responds to HTTP and doesn't immediately upgrade to HTTPS? I'm having a hard time imagining a scenario where I manage a web server that is accessible to anonymous people running pen scanners on it that has a justifiable reason for broadcasting port 80.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#119Shopify, Uber used to be at the top of the list.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#120Pro tip if you are a startup and want free security advice. Just sign up for all the bounty sites and for every single bounty just tell the submitter that it is a duplicate bug and pay them nothing, then hot patch it immediately and when they get suspicious tell them that their bug report had absolutely nothing to do with the timing of your patch. I know there are companies that do this because I have had it happen t…