- Hands-On Bug Hunting for Penetration Testers
- Joseph Marshall
- 151字
- 2021-07-16 17:53:04
Company-Sponsored Initiatives
Company-sponsored programs are just what they sound like. It's not just large mega-corps that have bounty programs – a surprising number of businesses have a process for rewarding security contributions. The size of each company can drastically effect the requirements and conditions for a reward: large companies pay top dollar for vulnerabilities, but the low-hanging fruit of those flaws will already have been picked; start-ups will have less mature applications, but probably a smaller application attack surface, assembled from a newer stack with fewer known vulnerabilities, and might want to pay for contributions in swag. Companies that are mature enough to suffer from technical debt, but also have a budget to pay rewards, are a nice fit. Sometimes, though, you'll just have to poke around in different areas, taking your chances, to find your next vulnerability.
Here are some examples of the programs offered by larger companies.
- CTF實戰:技術、解題與進階
- 數字身份與元宇宙信任治理
- Securing Blockchain Networks like Ethereum and Hyperledger Fabric
- Metasploit Penetration Testing Cookbook(Second Edition)
- 腦洞大開:滲透測試另類實戰攻略
- 網絡空間安全:管理者讀物
- 安全實戰之滲透測試
- 移動APT:威脅情報分析與數據防護
- 局域網交換機安全
- 學電腦安全與病毒防范
- 空間群組密鑰管理研究:基于自主的深空DTN密鑰管理
- 黑客攻防實戰從入門到精通
- VMware vCloud Security
- Mastering Malware Analysis
- 黑客攻防從入門到精通:命令版