官术网_书友最值得收藏!

Google

Google's program is expansive, with detailed payout structures and specific instructions for classifying different types of bug. Most of the relevant information can be found on the rewards section of their Application Security page, but Google also curates a (small) set of pentesting tutorials, with specific attention paid to finding the types of bugs and submitting the kinds of reports about them that Google wants to receive.

The articles on Bughunter University and other Google resources have different levels of applicability  some of it is just Google's preferences, requirements, and so on  but even the more idiosyncratic sections contain best practices and wisdom that can applied to other programs and engagements. Other companies might not agree completely with their common types of non-qualifying report, but there'll still be substantial overlap, making it a useful guide regardless of the vendor.

In addition to the materials on Bughunter University, Google is responsible for creating and maintaining a lot of great instructional applications. We'll be using one, Google Gruyere (https://google-gruyere.appspot.com/), as part of our chapter on XSS and you can find other great resources from Google in the other tools section at the end of the book.

主站蜘蛛池模板: 邹城市| 上饶县| 五华县| 小金县| 昭通市| 营山县| 汕头市| 东乡县| 法库县| 韩城市| 丘北县| 含山县| 南安市| 思茅市| 上杭县| 噶尔县| 当涂县| 措勤县| 平陆县| 松滋市| 托里县| 禹城市| 嵩明县| 遵化市| 瑞昌市| 巧家县| 长宁区| 隆安县| 邢台市| 普兰店市| 静海县| 黑龙江省| 新丰县| 宁都县| 伊金霍洛旗| 新安县| 郯城县| 广水市| 内乡县| 舒城县| 抚远县|