Earlier quoted context omitted.
I don't know any program except FB with such bounties for bugs in web apps. If you want to hack for money, focus on FB forget about others.
Google has one: https://www.google.com/about/appsecurity/reward-program/
Popping a shell on the Oculus developer portal
11–17 of 17 posts
Re: Popping a shell on the Oculus developer portal
#12Re: Popping a shell on the Oculus developer portal
#13Re: Popping a shell on the Oculus developer portal
#14I haven't seen the BENCHMARK trick before. It's very clever - a variation on timing failed login/password attempts. This is a clear and effective writeup. Congrats OP.
Can you explain? To me it just looks like a way to prove the exploit exists without revealing any actual injections.
Re: Popping a shell on the Oculus developer portal
#15I haven't seen the BENCHMARK trick before. It's very clever - a variation on timing failed login/password attempts. This is a clear and effective writeup. Congrats OP.
> It's very clever - a variation on timing failed login/password attempts. Can you explain? To me it just looks like a way to prove the exploit exists without revealing any actual injections.
https://www.owasp.org/index.php/Blind_SQL_Injection#Time-bas...
Re: Popping a shell on the Oculus developer portal
#16Security researchers are some of the most banal people. But I won't argue with $25k. ;-P
Re: Popping a shell on the Oculus developer portal
#17Earlier quoted context omitted.
Sign up for Bugcrowd and give it a go in your spare time. I would say it pays really well, in that it forces you to exercise and stretch your brain, over time you'll start getting better and work to the point you could quit your day job and do security full time.
How do things like bugcrowd (and bug bounties in general) work from a legal point of view? It seems very risky to go poking around without some kind of formal contract with the target.