Popping a shell on the Oculus developer portal
bitquark.co.uk
Popping a shell on the Oculus developer portal
1–10 of 17 posts
Re: Popping a shell on the Oculus developer portal
#2This was done after Facebook announced that Oculus is a part of their Whitehat program. OP was awarded 25000$ total for finding the vulnerabilities.
Very effective.
Re: Popping a shell on the Oculus developer portal
#3Re: Popping a shell on the Oculus developer portal
#4I liked this. I also wonder if it'd be worthwhile for me to take a few months off of work and try just poking away at security bounty programs. I doubt it would pay off to start with, but it seems like a pretty lucrative path. I know the OWASP Top 10, but don't really know my way around Burp Suite or anything.
Re: Popping a shell on the Oculus developer portal
#5I liked this. I also wonder if it'd be worthwhile for me to take a few months off of work and try just poking away at security bounty programs. I doubt it would pay off to start with, but it seems like a pretty lucrative path. I know the OWASP Top 10, but don't really know my way around Burp Suite or anything.
I don't know any program except FB with such bounties for bugs in web apps. If you want to hack for money, focus on FB forget about others.
Re: Popping a shell on the Oculus developer portal
#6This is a clear and effective writeup. Congrats OP.
Re: Popping a shell on the Oculus developer portal
#7I liked this. I also wonder if it'd be worthwhile for me to take a few months off of work and try just poking away at security bounty programs. I doubt it would pay off to start with, but it seems like a pretty lucrative path. I know the OWASP Top 10, but don't really know my way around Burp Suite or anything.
I don't know any program except FB with such bounties for bugs in web apps. If you want to hack for money, focus on FB forget about others.
Re: Popping a shell on the Oculus developer portal
#8I liked this. I also wonder if it'd be worthwhile for me to take a few months off of work and try just poking away at security bounty programs. I doubt it would pay off to start with, but it seems like a pretty lucrative path. I know the OWASP Top 10, but don't really know my way around Burp Suite or anything.
Re: Popping a shell on the Oculus developer portal
#9I liked this. I also wonder if it'd be worthwhile for me to take a few months off of work and try just poking away at security bounty programs. I doubt it would pay off to start with, but it seems like a pretty lucrative path. I know the OWASP Top 10, but don't really know my way around Burp Suite or anything.
Re: Popping a shell on the Oculus developer portal
#10I liked this. I also wonder if it'd be worthwhile for me to take a few months off of work and try just poking away at security bounty programs. I doubt it would pay off to start with, but it seems like a pretty lucrative path. I know the OWASP Top 10, but don't really know my way around Burp Suite or anything.
Sign up for Bugcrowd and give it a go in your spare time. I would say it pays really well, in that it forces you to exercise and stretch your brain, over time you'll start getting better and work to the point you could quit your day job and do security full time.