官术网_书友最值得收藏!

Google

Google's program is expansive, with detailed payout structures and specific instructions for classifying different types of bug. Most of the relevant information can be found on the rewards section of their Application Security page, but Google also curates a (small) set of pentesting tutorials, with specific attention paid to finding the types of bugs and submitting the kinds of reports about them that Google wants to receive.

The articles on Bughunter University and other Google resources have different levels of applicability  some of it is just Google's preferences, requirements, and so on  but even the more idiosyncratic sections contain best practices and wisdom that can applied to other programs and engagements. Other companies might not agree completely with their common types of non-qualifying report, but there'll still be substantial overlap, making it a useful guide regardless of the vendor.

In addition to the materials on Bughunter University, Google is responsible for creating and maintaining a lot of great instructional applications. We'll be using one, Google Gruyere (https://google-gruyere.appspot.com/), as part of our chapter on XSS and you can find other great resources from Google in the other tools section at the end of the book.

主站蜘蛛池模板: 靖安县| 遂平县| 越西县| 桦川县| 泰来县| 呼玛县| 长宁区| 营口市| 连江县| 丰镇市| 永兴县| 威海市| 金山区| 五原县| 江安县| 九江市| 宁城县| 通江县| 崇明县| 紫金县| 广平县| 年辖:市辖区| 信宜市| 阿拉善左旗| 平昌县| 汶上县| 贵定县| 金寨县| 广南县| 阳泉市| 义乌市| 株洲市| 永靖县| 云林县| 柘荣县| 邹平县| 大洼县| 永年县| 满城县| 麦盖提县| 张家界市|