5 ms·
Popping a shell on the Oculus developer portal
- readerrrr 12y agoIf you didn't read: This was done after Facebook announced that Oculus is a part of their Whitehat program. OP was awarded 25000$ total for finding the vulnerabilities. Very effective.
- canadev 12y agoI liked this. I also wonder if it'd be worthwhile for me to take a few months off of work and try just poking away at security bounty programs. I doubt it would pay off to start with, but it seems like a pretty lucrative path. I know the OWASP Top 10, but don't really know my way around Burp Suite or anything.
- homakov 12y agoI don't know any program except FB with such bounties for bugs in web apps. If you want to hack for money, focus on FB forget about others.
- rqebmm 12y agoGoogle has one: https://www.google.com/about/appsecurity/reward-program/ https://www.google.com/about/appsecurity/reward-program/
- homakov 12y agoThey pay ten times less
- christop 12y agohttps://hackerone.com/programs https://hackerone.com/programs
- homakov 12y agoWhich one is profitable there?
- phaus 12y agoIf you decide to give it a shot, pay close attention to the policies and procedures that companies post. Facebook has refused to pay people in the past because they didn't use the framework/channels that they have provided.
- dsl 12y agoSign up for Bugcrowd and give it a go in your spare time. I would say it pays really well, in that it forces you to exercise and stretch your brain, over time you'll start getting better and work to the point you could quit your day job and do security full time.
- voltagex_ 12y agoI haven't seen the BENCHMARK trick before. It's very clever - a variation on timing failed login/password attempts. This is a clear and effective writeup. Congrats OP.
- andypants 12y ago> It's very clever - a variation on timing failed login/password attempts. Can you explain? To me it just looks like a way to prove the exploit exists without revealing any actual injections.
- 1c4050b09 12y agoIt's a pretty common technique for exploiting Blind SQLi. You can use this as the one of the Branches in a SELECT IF to be able to determine the value of something in the DB. https://www.owasp.org/index.php/Blind_SQL_Injection#Time-based https://www.owasp.org/index.php/Blind_SQL_Injection#Time-bas...
- iamleppert 12y agoSecurity researchers are some of the most banal people. But I won't argue with $25k. ;-P
- zuck9 12y agoI don't think so. There's creativity in hacking any server. You won't find a straight same path every time. I think security researchers are the most patient people or most determined.