- Hands-On Bug Hunting for Penetration Testers
- Joseph Marshall
- 138字
- 2021-07-16 17:53:06
The Internet Bug Bounty Program
The internet bug bounty program inhabits something between a third-party marketplace and an individual effort. The IBBP is a not-for-profit funded by big tech contributors such as Microsoft, Adobe, Facebook, and GitHub, for the purpose of protecting the integrity of core internet services. The technologies covered under their reward program are diverse, with languages (Perl, Ruby, PHP), application frameworks (Django, Ruby on Rails), servers (NGINX, Apache HTTP) and cryptographic tools (Open SSL) all covered.
While this work is focused primarily on pentesting web applications as opposed to their more fundamental components, the IBBP is a great resource to keep in mind as your skills advance. The IBBP has been responsible for awarding payouts for some of the most high-profile bugs in the last decade, such as Heartbleed ($15k), ShellShock ($20k), and ImageTragick ($7.5k).
- 攻守道:企業數字業務安全風險與防范
- 信息安全導論(在線實驗+在線自測)
- Securing Blockchain Networks like Ethereum and Hyperledger Fabric
- 暗戰亮劍:黑客滲透與防御全程實錄
- 計算機使用安全與防護
- 黑客攻防與無線安全從新手到高手(超值版)
- 數據安全與隱私計算(第3版)
- Kerberos域網絡安全從入門到精通
- 信息安全等級保護測評與整改指導手冊
- 無線傳感器網絡安全與加權復雜網絡抗毀性建模分析
- 華為Anti-DDoS技術漫談
- Kali Linux高級滲透測試(原書第4版)
- 一本書讀透金融科技安全
- HTTPS權威指南:在服務器和Web應用上部署SSL/TLS和PKI
- 互聯網金融法律與風險控制(第2版)