Live data from Hacker News

Teen Becomes First Hacker to Earn $1M Through Bug Bounties

digit.fyi

161–170 of 178 posts

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#161

Earlier quoted context omitted.

Can you elaborate on the automated reports a bit more? What makes them uninteresting?

I don't run a bug bounty but I do sit on a security@ inbox. I don't believe I've ever seen a report I would want to pay out on even if I could, but if you discount blatant spam (often peddling EV certificates), I've received reports asking about bounties for: - nginx version disclosed in headers - "Feature-Policy" header missing - DNSSEC not set up on zone - Domain not in HSTS preload list Responding to this sort of…

I remember back in the day I used to field security scan reports for a client I consulted for, and the amount of things I had to mark as "not actually a problem" because all they did was check Apache header versions was staggering. This is slightly better than and slightly worse than your situation at the same time. Slightly better in that they were looking for versions that had actual exploits known in them, but slightly worse in that they had no way to deal with distros that back-patched for vulnerabilities, like RHEL (which was the distro in question). "Yes, I'm aware that that the version of Apache you are noting contains a vulnerability. No, it's not actually a problem or exploitable, since I already applied the patched update. Just like last week. And the week before that."

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#162

Earlier quoted context omitted.

Could you elaborate on this? I'm curious as to how a setup like this would work in practice. Many people in my family live in rural areas so the topic of restricted bandwidth/poor connection quality is of great interest to me.

https://meyerweb.com/eric/thoughts/2018/08/07/securing-sites... “But there I stood anyway, hoping my requests to load simple web pages would bear fruit, and I could continue teaching basic web principles to a group of vocational students. Because Wikipedia wouldn’t cache. Google wouldn’t cache. Meyerweb wouldn’t cache. Almost nothing would cache. Why? HTTPS.”

Thanks for the excellent link, discussed on HN a while ago [1]. For those that think an sslstriping proxy would solve it please remember that this would degrade the security for requests that really have to be encrypted.

[1] https://news.ycombinator.com/item?id=17707187

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#163

Earlier quoted context omitted.

Hopefully, probably sarcastic, but just in case you're not: who puts the data on the blockchain?

The company posting the bounty. Third party verifies the bug. Why sarcastic?

Why doesn’t the third party publish the data themselves then?

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#164
post #77

Earlier quoted context omitted.

SFBA income tax, state and federal, would leave about 55% of that, then, so, as usual, California is expensive.

Income taxes are more like 30% of that. It’s expensive, but not that expensive. Unless you’re counting rent in that, but even then I think half is pushing it.

Actually 39.04% according to this website. Still, 30% is closer to correct than 55%.

https://smartasset.com/taxes/income-taxes

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#165

Earlier quoted context omitted.

But no one is going to pay $330k to a 17 year old with no experience

Well, they did, right? So that doesn't seem true.

By "no one" crapbone meant no single employer. And no single employer paid Santiago the money. It was paid by a group of companies each paying bounties for different bugs.

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#166
post #33

Pro tip if you are a startup and want free security advice. Just sign up for all the bounty sites and for every single bounty just tell the submitter that it is a duplicate bug and pay them nothing, then hot patch it immediately and when they get suspicious tell them that their bug report had absolutely nothing to do with the timing of your patch. I know there are companies that do this because I have had it happen t…

Maybe you could call them out on Twitter? Or maybe in the future you could submit most of the bug but hold back something critical until they acknowledge it?

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#167
post #36
post #33

Pro tip if you are a startup and want free security advice. Just sign up for all the bounty sites and for every single bounty just tell the submitter that it is a duplicate bug and pay them nothing, then hot patch it immediately and when they get suspicious tell them that their bug report had absolutely nothing to do with the timing of your patch. I know there are companies that do this because I have had it happen t…

I don't doubt your lived experience, but for real companies, the economics of ruthlessly withdrawing bounties don't make sense; bounties just don't cost enough money to be worth picking fights over. There are some patterns where I've seen people not get paid just on general principle; for instance, people find systemic issues and, rather than disclosing the root cause, try to claim bounties for every instance of the…

Large companies sometimes do unethical things just because one person or a group of people at them thinks it is a good idea, unrelated to any measurable economic benefit.

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#168

Earlier quoted context omitted.

One of the best introductions to the field is going through overthewire’s bandit vulnerability games. https://overthewire.org/wargames/bandit/ They have 30+ levels where you ssh into a server and attempt to find some type of vulnerability. They start out very easy and get tough quick. It’s very eye opening to see the types of exploits that exist. They also have a set of challenges aimed at serverside web security. ht…

> One of the best introductions to the field is going through overthewire’s bandit vulnerability games. Out of curiosity I visited your first link and played the first dozen+ levels. It's just been bash-fu and occasional man reading/googling. Judging by the subsequent level instructions I went through, there didn't seem to be much more in there. I'm like, if you really want to learn more about shell commands, there a…

bandit is just the beginner intro to shell series that is meant for pure beginners to unix, you didnt miss anything. All of the other games on there are actual wargames to learn about security

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#169
post #18

Earlier quoted context omitted.

> understanding data structures and algorithms doesn't necessarily correlate to one's ability to identify security vulnerabilities. No, but it does suggest that you're likely capable of learning security work. Just like your data structure and algorithm knowledge didn't come for free, nobody is born knowing how to find security problems. You need to work for it.

What's a way to learn security work? Genuinely curious.

I learned a tremendous amount from Root-Me [1], it has a strong community and is _often_ updated with new challenges.

1: https://www.root-me.org/?lang=en

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#170
post #33

Pro tip if you are a startup and want free security advice. Just sign up for all the bounty sites and for every single bounty just tell the submitter that it is a duplicate bug and pay them nothing, then hot patch it immediately and when they get suspicious tell them that their bug report had absolutely nothing to do with the timing of your patch. I know there are companies that do this because I have had it happen t…

Well I do freelance work at a client which paid out about 20k in bounties in the last few weeks.

10k was for a bug that had actually been found by the internal test-team on a Friday after a new release on Wednesday. Over the weekend however, a bounty hunter/pen-tester discovered the same thing...

There was some internal discussion (certainly because an internal ticket existed with an extensive discussion) about paying out this bounty - but eventually was decided to not bother with it and not get a rep of screwing over bounty hunters/pen-testers, certainly because this was a guy they already worked with before, and they had actually informed him and a few others specifically about the new release that Wednesday.

They did inform the guy that the internal testing had already found this, but since it was still open on the public-facing service at the time he reported it, they would pay him.

Post reply on HN