Running a Bug Bounty Program
What you need to know
Running a Bug Bounty Program What you need to know Shpend TU - - - PowerPoint PPT Presentation
Running a Bug Bounty Program What you need to know Shpend TU - Master in Software Engineering Senior AppSec Engineer & Team Lead @ Bugcrowd Bug bounty Hunter Video Games Bsides Vienna 2016 Agenda What & Why
What you need to know
Bsides Vienna 2016
Bsides Vienna 2016
Source (Hyperbole and a Half) Bsides Vienna 2016
The History of Bug Bounties: Abbreviated Timeline from 1995 to Present
Bsides Vienna 2016
Source (Hyperbole and a Half) Bsides Vienna 2016
Source (ESRB) Bsides Vienna 2016
2013 (Pentest) 2014 (Bug Bounty) 2015 (Bug Bounty) Critical High 1 25 3 Medium 1 8 2 Low 2 16 5
Bsides Vienna 2016 Source (Canvas)
https://www.canvaslms.com/security
Source (ESRB) Bsides Vienna 2016
Source (ESRB) Bsides Vienna 2016
Source (RedTeam Pentesting) Bsides Vienna 2016
Bsides Vienna 2016
○ Scope ○ Exclusions ○ Environment ○ Access
○ Handling Submissions (Manpower) ○ Communicating Effectively ○ Defining a Vulnerability Rating Taxonomy
Bsides Vienna 2016
Source (Get A Life) Bsides Vienna 2016
○ Only webapp (www.example.com) ○ All subdomains (careful) (*.example.com) ○ All products & acquisitions (more careful) ○ Mobile? (Android, iOS, Windows Phone? j/k) ○ Human & physical
Source (Accurate Shooter) Bsides Vienna 2016
○ No security impact (Logout csrf) ○ Best practice (Session management) ○ Full/partial poc? (XXE, SSRF,SQLI)
○ Min and Max ○ Table based on vuln types
○ Allowed or not
Source (Accurate Shooter) Bsides Vienna 2016
○ (Low-impact) “low hanging fruit” ○ Intended functionality ○ Known issues (call out!) ○ Accepted risks ○ Issues based on pivoting
Source (Meme Generator) Bsides Vienna 2016
○ Scanners ○ Contact forms ○ Pentesting requests
○ IoT/devices
Source (The Daily Mail) Bsides Vienna 2016
○ E.g. sandbox credit cards
Source (Demotivation) Bsides Vienna 2016
Bsides Vienna 2016 Source (Meme Generator)
Bsides Vienna 2016 Source (Meme Generator)
Bsides Vienna 2016 Source (Meme Generator)
○ Concise, unambiguous responses ■ ESL ○ Short response time ○ Predictable reward time
Bsides Vienna 2016 Source (Profielwekstuk)
○ Speeds up triage process ○ Track your organization’s security posture ○ Arrive at a reward amount more quickly
○ Focus on high-value bugs ○ Avoid wasting time on non-rewardable bugs ○ Alongside brief, helps build trust
Bsides Vienna 2016
○ Review interesting bugs ○ Discuss additions ○ Propose changes
Bsides Vienna 2016 Source (Wikipedia)
Source (Meme Generator) Bsides Vienna 2016
Source (Meme Generator) Bsides Vienna 2016
SSO account
address
Source (Meme Generator) Bsides Vienna 2016
Shpend Kurtishaj me@shpendk.com @shpendk
Thanks!
Source (xkcd)