5 ms·
$9000 bounty paid for Python bugs
- taspeotis 12y ago$9000 bounty paid for Python bug (hackerone.com) There's 10 of them. So, $900 paid out for each one. A job well done in discovering and disclosing them and the payout is generous nonetheless, but the title is wrong.
- butwhy 12y agoWell the issue focused on one key point (integer overflow). As for your speculation that it is $900 per bug, that is wrong, too. The minimum payout per bug is $1500. I don't really care about the semantics, so you'll have to deal with the title.
- stingraycharles 12y agoAn easy fix would be to rename "bug" to "bugs", then everyone should be happy.
- dsacco 12y agoAs a security engineer, I'm really happy to see news like this enter the mainstream more and more on HN. These bounties are well deserved. For those of you who would like to try and earn bounties like these, I recommend the same books I always do: 1. The Art of Software Security Assessment 2. Gray Hat Python 3. The Web Application Hacker's Handbook This is your ethical hacker starter kit. The first two are good for foundational knowledge and will show you how to find the bugs worth something. The third book is specialized for web applications, which is still great but not quite as lucrative. You will also want to check out CTFs, Cryptography Engineering and the Matasano Crypto Challenges. If you're looking to join a top tier security firm, Matasano is great for those who like offices and Accuvant (my employer) is great for those who like working fully remotely.
- lordnacho 12y agoThanks for the list. I always found the security area mystifying. How do you determine when you are good enough to apply? And how do you get some work that you will actually be able to do?
- dsacco 12y agoSome firms are very open to taking total noobs with promising intuitions and who can code well (you need to be able to code well for this). If you can go this way, you should. Otherwise: 1. If you have found bug bounties consistently across the gamut of web application vulnerabilities, you're probably ready (you will have gaps - supplement with lots of theory). 2. If you can competently write a custom debugger and reverse engineer apps, you're ready. 3. If you would honestly call yourself an expert C/C++ programmer, you're ready. 4. If you actually completed the Matasano Crypto Challenges, you're ready. You are specifically not ready just because you got yourself a certification, especially if that certification is the CISSP. The CISSP is an HR drone criteria that has more relevance on a SaaS pricing table than it does in a real security firm. 'tptacek and 'patio11 are working on Starfighter, which will be of interest to you. Check it out.
- exDM69 12y agoThese books are probably great but if you look at some of the best/worst bugs found in the past few years, there's one tool that seems to come up over and over again: afl-fuzz. I recon that the easiest way to get started with bug hunting might be to just set up afl-fuzzing on some trivial code that has lots of potential for going wrong. Stuff like JSON/HTML/HTTP parsing in C is a great candidate to find integer overflow or buffer overrun bugs in (some of the bugs in this list are exactly that). Throw some CPU time for the fuzzing, and pretty soon you should have a handful of repro cases. The nice thing about these is that the bugs could be very trivial to fix but have enormous security consequences. If someone wants a suggestion for a project to try some fuzzing against, the new h2o/libh2o web server and its HTTP parser component (picohttpparser) look very well written but not very well tested (only a handful of hand written, hard coded test cases). I'm pretty sure there's one or more potentially disastrous bugs in it. edit: almost all bugs in this list seem to be integer overflow bugs. That hints that these issues were found using a static analysis tool like ClangAnalyzer or Coverity.
- inglesp 12y agoWhere's the $9000 come from?
- adricnet 12y agoHackerOne manages bug bounty campaigns / community vulnerability research for orgs and companies. This campaign is sponsored by FaceBook and Microsoft, according to this page: https://hackerone.com/internet-bug-bounty https://hackerone.com/internet-bug-bounty .
- eeZi 12y agohttps://hackerone.com/internet-bug-bounty https://hackerone.com/internet-bug-bounty Microsoft/Facebook.
- tanishalfelven 12y agoSoftware companies of late pay developers to find bugs in their security. Read more here: http://blog.codinghorror.com http://blog.codinghorror.com
- deleted 12y ago[deleted]