官术网_书友最值得收藏!

Finding Other Programs

Many companies have bug bounty programs. If there's a particular site or app you're interested in testing, finding out whether it's supported by a bug bounty is as easy as a couple of searches. Queries that take advantage of Google's expressive search syntax, such as inurl:/security/, intext:bug bounty, and intext:reward are all great building blocks you can use to discover new programs. You can even combine them to drill down into bounty programs that are specific to a certain application – a query such as intext:"Bug Bounty" AND intext:"vulnerability" AND intext:"reward" AND inurl:"/wp-content/"  can be used to return program pages for Wordpress sites (credit to Sachin Wagh (@tiger_tigerboy) for the dorks).

You can even set up a Google alert using these search terms and others, to give you a simple, automated way of discovering new programs to participate in.

For something a little less ad-hoc: in addition to the great teaching resources it provides, Bugcrowd curates a list populated by its members on what bug bounty programs are available as well as whether they provide financial compensation versus company swag, their age, and whether or not they feature a "Hall of Fame" for successful researchers. You can find the table at https://www.bugcrowd.com/bug-bounty-list/.

Firebounty, mentioned earlier as a product of YesWeH4ck, is a hybrid that shows that bounty programs from other platforms as well as its own unique offerings. As a product of the French security scene, it has an interesting mix of both transatlantic and European websites, mobile apps, and APIs.

主站蜘蛛池模板: 潍坊市| 武冈市| 黄山市| 景泰县| 六盘水市| 泽普县| 阳泉市| 卢湾区| 若羌县| 淮阳县| 贵港市| 肥西县| 玉环县| 郑州市| 潞城市| 库车县| 龙泉市| 绥棱县| 武陟县| 陈巴尔虎旗| 闵行区| 延庆县| 广水市| 海兴县| 昌乐县| 大庆市| 如东县| 类乌齐县| 泸水县| 景泰县| 上犹县| 固镇县| 武宁县| 巴里| 论坛| 平原县| 陆良县| 霍城县| 桦川县| 肇东市| 马公市|