- Hands-On Bug Hunting for Penetration Testers
- Joseph Marshall
- 152字
- 2021-07-16 17:53:05
GitHub
GitHub offers a bounty program that covers a wide array of its properties, including the API, enterprise app, and main rails site (https://github.com/), with payouts ranging from $555 to $20,000 for most of those targets.
One neat feature of the GitHub program is that each participant who successfully submits a bounty receives a profile page that – in addition to showing the points they've accumulated, rank, and earned badges – lists their reported vulnerabilities with a short technical blurb about each one. Like the published submission reports on other platforms, any technical detail about a successfully-discovered vulnerability is an invaluable insight into winning strategies, both in general and for the site in question.
And if you're looking to parlay finding bugs into a larger career in security, profile pages such as the ones offered by GitHub, Bugcrowd, and HackerOne can be great bullet points on your resume.
- INSTANT Burp Suite Starter
- 安全實戰(zhàn)之滲透測試
- 網(wǎng)絡安全技術及應用(第3版)
- 同態(tài)密碼學原理及算法
- Applied Network Security
- 網(wǎng)絡安全與攻防入門很輕松(實戰(zhàn)超值版)
- Kerberos域網(wǎng)絡安全從入門到精通
- Advanced Penetration Testing for Highly:Secured Environments(Second Edition)
- Web安全之深度學習實戰(zhàn)
- 信息安全等級保護測評與整改指導手冊
- 數(shù)據(jù)安全與流通:技術、架構與實踐
- Bug Bounty Hunting Essentials
- 信息安全工程與實踐
- 云計算安全防護技術
- BeagleBone for Secret Agents