Earlier quoted context omitted.
Can you elaborate on the automated reports a bit more? What makes them uninteresting?
I don't run a bug bounty but I do sit on a security@ inbox. I don't believe I've ever seen a report I would want to pay out on even if I could, but if you discount blatant spam (often peddling EV certificates), I've received reports asking about bounties for: - nginx version disclosed in headers - "Feature-Policy" header missing - DNSSEC not set up on zone - Domain not in HSTS preload list Responding to this sort of…
Teen Becomes First Hacker to Earn $1M Through Bug Bounties
161–170 of 178 posts
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#162Earlier quoted context omitted.
Could you elaborate on this? I'm curious as to how a setup like this would work in practice. Many people in my family live in rural areas so the topic of restricted bandwidth/poor connection quality is of great interest to me.
https://meyerweb.com/eric/thoughts/2018/08/07/securing-sites... “But there I stood anyway, hoping my requests to load simple web pages would bear fruit, and I could continue teaching basic web principles to a group of vocational students. Because Wikipedia wouldn’t cache. Google wouldn’t cache. Meyerweb wouldn’t cache. Almost nothing would cache. Why? HTTPS.”
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#163Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#164Earlier quoted context omitted.
SFBA income tax, state and federal, would leave about 55% of that, then, so, as usual, California is expensive.
Income taxes are more like 30% of that. It’s expensive, but not that expensive. Unless you’re counting rent in that, but even then I think half is pushing it.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#165Earlier quoted context omitted.
But no one is going to pay $330k to a 17 year old with no experience
Well, they did, right? So that doesn't seem true.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#166Pro tip if you are a startup and want free security advice. Just sign up for all the bounty sites and for every single bounty just tell the submitter that it is a duplicate bug and pay them nothing, then hot patch it immediately and when they get suspicious tell them that their bug report had absolutely nothing to do with the timing of your patch. I know there are companies that do this because I have had it happen t…
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#167Pro tip if you are a startup and want free security advice. Just sign up for all the bounty sites and for every single bounty just tell the submitter that it is a duplicate bug and pay them nothing, then hot patch it immediately and when they get suspicious tell them that their bug report had absolutely nothing to do with the timing of your patch. I know there are companies that do this because I have had it happen t…
I don't doubt your lived experience, but for real companies, the economics of ruthlessly withdrawing bounties don't make sense; bounties just don't cost enough money to be worth picking fights over. There are some patterns where I've seen people not get paid just on general principle; for instance, people find systemic issues and, rather than disclosing the root cause, try to claim bounties for every instance of the…
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#168Earlier quoted context omitted.
One of the best introductions to the field is going through overthewire’s bandit vulnerability games. https://overthewire.org/wargames/bandit/ They have 30+ levels where you ssh into a server and attempt to find some type of vulnerability. They start out very easy and get tough quick. It’s very eye opening to see the types of exploits that exist. They also have a set of challenges aimed at serverside web security. ht…
> One of the best introductions to the field is going through overthewire’s bandit vulnerability games. Out of curiosity I visited your first link and played the first dozen+ levels. It's just been bash-fu and occasional man reading/googling. Judging by the subsequent level instructions I went through, there didn't seem to be much more in there. I'm like, if you really want to learn more about shell commands, there a…
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#169Earlier quoted context omitted.
> understanding data structures and algorithms doesn't necessarily correlate to one's ability to identify security vulnerabilities. No, but it does suggest that you're likely capable of learning security work. Just like your data structure and algorithm knowledge didn't come for free, nobody is born knowing how to find security problems. You need to work for it.
What's a way to learn security work? Genuinely curious.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#170Pro tip if you are a startup and want free security advice. Just sign up for all the bounty sites and for every single bounty just tell the submitter that it is a duplicate bug and pay them nothing, then hot patch it immediately and when they get suspicious tell them that their bug report had absolutely nothing to do with the timing of your patch. I know there are companies that do this because I have had it happen t…
10k was for a bug that had actually been found by the internal test-team on a Friday after a new release on Wednesday. Over the weekend however, a bounty hunter/pen-tester discovered the same thing...
There was some internal discussion (certainly because an internal ticket existed with an extensive discussion) about paying out this bounty - but eventually was decided to not bother with it and not get a rep of screwing over bounty hunters/pen-testers, certainly because this was a guy they already worked with before, and they had actually informed him and a few others specifically about the new release that Wednesday.
They did inform the guy that the internal testing had already found this, but since it was still open on the public-facing service at the time he reported it, they would pay him.