- Hands-On Bug Hunting for Penetration Testers
- Joseph Marshall
- 152字
- 2021-07-16 17:53:05
GitHub
GitHub offers a bounty program that covers a wide array of its properties, including the API, enterprise app, and main rails site (https://github.com/), with payouts ranging from $555 to $20,000 for most of those targets.
One neat feature of the GitHub program is that each participant who successfully submits a bounty receives a profile page that – in addition to showing the points they've accumulated, rank, and earned badges – lists their reported vulnerabilities with a short technical blurb about each one. Like the published submission reports on other platforms, any technical detail about a successfully-discovered vulnerability is an invaluable insight into winning strategies, both in general and for the site in question.
And if you're looking to parlay finding bugs into a larger career in security, profile pages such as the ones offered by GitHub, Bugcrowd, and HackerOne can be great bullet points on your resume.
- Extending Symfony2 Web Application Framework
- DevSecOps敏捷安全
- unidbg逆向工程:原理與實踐
- 可信計算3.0工程初步
- 電子支付的規(guī)制結(jié)構(gòu)配置研究
- 計算機(jī)病毒分析與防范大全(第3版)
- 計算機(jī)使用安全與防護(hù)
- .NET安全攻防指南(上冊)
- 同態(tài)密碼學(xué)原理及算法
- 網(wǎng)絡(luò)空間安全實驗
- 編譯與反編譯技術(shù)實戰(zhàn)
- 網(wǎng)絡(luò)關(guān)鍵設(shè)備安全檢測實施指南
- 網(wǎng)絡(luò)服務(wù)安全與監(jiān)控
- 網(wǎng)絡(luò)空間安全導(dǎo)論
- Mastering Metasploit