官术网_书友最值得收藏!

HackerOne

HackerOne (https://www.hackerone.com/) is a similar platform – it has its own point system (reputation) and also calculates a variety of metrics that it uses as the basis for its Leaderboard and for invitations to its own private programs.

Like Bugcrowd, it also has a bug bounty policy for itself – if you find a vulnerability in one of its sites or apps, you're entitled to a reward. Interestingly though, you might still be entitled to a reward even if you don't discover a bug. From their site:


"HackerOne is interested in your research on our systems, regardless of whether you found a security vulnerability. If you have found yourself looking at a particular feature on one of our assets but didn't find anything, please submit a report that describes all the different things you tried and failed. We may reward you for substantial research performed on assets under our bug bounty policy."

This is an usual policy that still makes sense: providing a detailed list of everything that worked is its own audit of the company's resources, even if it doesn't cover any vulnerable areas.

HackerOne and Bugcrowd both have a similar breadth of different companies, with different products, business models, and security needs. HackerOne does have a few notable companies that are exclusive to its platform, most notably Twitter, but generally the offerings are very similar.

主站蜘蛛池模板: 容城县| 新泰市| 武汉市| 新竹县| 晋宁县| 海兴县| 搜索| 喀喇沁旗| 清新县| 平武县| 台湾省| 临湘市| 巴林右旗| 德化县| 图们市| 克拉玛依市| 葵青区| 大理市| 千阳县| 水城县| 鄄城县| 桂林市| 保定市| 老河口市| 辰溪县| 峨眉山市| 武强县| 金沙县| 陆川县| 肃北| 洛川县| 报价| 木兰县| 六枝特区| 闵行区| 南和县| 阳高县| 丹棱县| 长寿区| 阿图什市| 黄山市|