- The Guide to Finding and Reporting Web Vulnerabilities
- About the Author
- About the Tech Reviewer
- Foreword
- Introduction
- Who This Book Is For
- What Is In This Book
- Happy Hacking!
- 1 Picking a Bug Bounty Program
- 2 Sustaining Your Success
- 3 How the Internet Works
- 4 Environmental Setup and Traffic Interception
- 5 Web Hacking Reconnaissance
- 6 Cross-Site Scripting
- 7 Open Redirects
- 8 Clickjacking
- 9 Cross-Site Request Forgery
- 10 Insecure Direct Object References
- 11 SQL Injection
- 12 Race Conditions
- 13 Server-Side Request Forgery
- 14 Insecure Deserialization
- 15 XML External Entity
- 16 Template Injection
- 17 Application Logic Errors and Broken Access Control
- 18 Remote Code Execution
- 19 Same-Origin Policy Vulnerabilities
- 20 Single-Sign-On Security Issues
- 21 Information Disclosure
- 22 Conducting Code Reviews
- 23 Hacking Android Apps
- 24 API Hacking
- 25 Automatic Vulnerability Discovery Using Fuzzers
文章来源于网络收集而来,版权归原创者所有,如有侵权请及时联系!
A Quick Comparison of Popular Programs
After you’ve identified a few programs that you are interested in, you could list the properties of each one to compare them. In Table 1-1 , let’s compare a few of the popular programs introduced in this chapter.
在确定了感兴趣的几个计划后,您可以列出每个计划的属性进行比较。在表 1-1 中,让我们比较本章介绍的几个热门计划。
Table 1-1 : A Comparison of Three Bug Bounty Programs: HackerOne, Facebook, and GitHub
表格 1-1:三个漏洞赏金计划的比较:HackerOne、Facebook 和 GitHub。
Program | Asset type | In scope | Payout amount | Response time |
HackerOne | Social site | https://hackerone.com/ https://api.hackerone.com *.vpn.hackerone.net https://www.hackerone.com And more assets . . . Any vulnerability except exclusions are in scope. | $500–$15,000+ | Fast. Average time to response is 5 hours. Average time to triage is 15 hours. |
Social site, nonsocial site, mobile site, IoT, and source code | Instagram Internet.org / Free Basics Oculus Workplace Open source projects by Facebook Portal FBLite Express Wi-Fi Any vulnerability except exclusions are in scope. | $500 minimum | Based on my experience, pretty fast! | |
GitHub | Social site | https://blog.github.com/ https://community.github.com/ http://resources.github.com/ And more assets . . . Use of known-vulnerable software. Clickjacking a static site. Including HTML in Markdown content. Leaking email addresses via .patch links. And more issues . . . | $617–$30,000 | Fast. Average time to response is 11 hours. Average time to triage is 23 hours. |
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论