Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
SamHoustonCM
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
SamHoustonCM
8mo ago
>We recently came across a suspicious NPM package called `buildrunner-dev`. The package is deceptively simple, containing a package.json with a postinstall hook pointed at an `init.js` file, but that’s where things got interesting. >T
2.
▲
Malicious NPM Package Hides Pulsar .NET Malware Inside PNG Images
(veracode.com)
2 points
by
SamHoustonCM
8mo ago
|
1 comments
3.
▲
"Absurd" 12-step malware dropper spotted in malicious NPM packages
(thestack.technology)
3 points
by
SamHoustonCM
1y ago
|
1 comments
4.
▲
Apache Struts2 CVE-2023-50164, File Upload Vulnerability Analysis
(labs.greynoise.io)
2 points
by
SamHoustonCM
3y ago
|
2 comments
5.
▲
by
SamHoustonCM
3y ago
Matthew Remacle (Remy) digs into the newly disclosed Apache Struts2 CVE-2023-50164 file upload vulnerability. This weakness allows an attacker to drop a web shell that can be called remotely through a public interface over defined routes. A
6.
▲
by
SamHoustonCM
4y ago
Why does Heroku have so many uptime issues? Seems to be happening every few months. Last week there was downtime, now again... Is Salesforce committed to Heroku?
7.
▲
by
SamHoustonCM
8y ago
(Full disclosure, I work at Bugcrowd) Check out Bugcrowd.com - we can manage the whole thing for you and we can even give your dev team remediation advice/information so that they can fix it. We've been doing this stuff for severa
8.
▲
by
SamHoustonCM
9y ago
There's a blog post on Bugcrowd about note taking techniques. Might be helpful for you! :) https://blog.bugcrowd.com/the-importance-of-notes-session-tr...
9.
▲
by
SamHoustonCM
9y ago
Awesome! Great to hear. Feel free to ping me if you have questions.
10.
▲
by
SamHoustonCM
9y ago
There are a ton of different directions that you can head in and focus on. I encourage you to start/look at stuff that you're genuinely interested in and excited about. I've written a "Getting Started" guide for sec
11.
▲
by
SamHoustonCM
10y ago
Right but the cost differential between staffing it yourself and paying someone else to do it is substantial. Doing it yourself will cost you 3-5x more than paying someone else who is able to do it at scale.
12.
▲
by
SamHoustonCM
10y ago
(Disclosure: I work for Bugcrowd) That's why we suggest going with a 'managed' bounty. That's where Bugcrowd triages all of the incoming bugs and then passes along the valid bugs for you to prioritize and reward. It cuts
13.
▲
by
SamHoustonCM
10y ago
Were you recruited to work on the bounty?
14.
▲
by
SamHoustonCM
10y ago
Agreed with others that it's worth considering a small private program. You can do time boxed bounties with a capped cost, that way you're getting results without committing to a huge budget. Check out Bugcrowd's "on dem
15.
▲
by
SamHoustonCM
11y ago
New programs are launching all the time or the scope of current programs is expanding out to include new products or features. It's never too late to get started, there's actually more work than researchers at the moment and it wi
16.
▲
Tesla launches a bug bounty program
(bugcrowd.com)
4 points
by
SamHoustonCM
11y ago
|
0 comments
17.
▲
by
SamHoustonCM
11y ago
Yeah,running a public program and are handling a lot of submissions (pretty typical), handling the volume of bugs and evaluating them quickly can be quite tricky. Not only is it important for the company because you want to make sure you&#x
18.
▲
How a Facebook Ad led to a job at a startup
(medium.com)
2 points
by
SamHoustonCM
13y ago
|
0 comments