Bug bounty cash for hack

28
#Remember?

Transcript of Bug bounty cash for hack

Page 1: Bug bounty cash for hack

#Remember?

Page 2: Bug bounty cash for hack

# And?

Page 3: Bug bounty cash for hack

One More last And

Page 4: Bug bounty cash for hack

What Common?

#BugBounty

Page 5: Bug bounty cash for hack

Bug Bounty

Cash for Hack

Page 6: Bug bounty cash for hack

Who Am I (#whoami)

Atul Shedage

@atul_shedage

Page 7: Bug bounty cash for hack

Instructor at suruji.com

Bug Bounty Hunter (only when ever I run out of money :P)

Creator of SVWA (suruji vulnerable web application)

Laravel Developer (PHP Framework)

Bsc Graduate (Msc Under Progress)

Page 8: Bug bounty cash for hack

Lucky Enough

Page 9: Bug bounty cash for hack

And

Page 10: Bug bounty cash for hack

Anddddd

Page 11: Bug bounty cash for hack

Agenda

• What is BugBounty.

• History.

• Why to join BugBounty.

• Bug Bounty Programs and Platforms.

• How to Start with Bug Bounties.

• Tools to Use.

• Reporting / Bug Submission

• My Experience with Bug Bounty.

Page 12: Bug bounty cash for hack

What is #BugBounty?

• Also called As VRP (Vulnerability Reward Program)

• Company (Security Team/Vendor) Create Program. Offer Cash , HOF , Swag. Fix Bugs. Acknowledge Your work.

• Researchers / Bug Hunter Hit Target and Get Bugs. Sometimes Duplicates , Sometime $$$ , Sometimes Swag. Recheck Bug after fix. Write Blog Post.

Page 13: Bug bounty cash for hack

History

Image Credit crowdcurity.com

Page 14: Bug bounty cash for hack

Why to Join BugBounty?

• $$$$

• Swag (Tshirts + Stickers + Mugs + Company Gadgets)

• Free Service

• HOF

Page 15: Bug bounty cash for hack

Bug Bounty Program and Platform

• Popular Programs– Google (Min 100$ & Max 20000$)

– Yahoo (Min 50$ & Max 15000$)

– Facebook (Min 500$)

– Want to know more?• Github

• Twitter

• Etsy

Page 16: Bug bounty cash for hack

Want few more?

• https://bugcrowd.com/list-of-bug-bounty-programs/

• https://hackerone.com/programs

• https://www.crowdcurity.com/programs

Page 17: Bug bounty cash for hack

Popular Platform

• BugCrowd

– Managed Security Programs for company

– 14300 world wide researchers

– 200+ Programs

• HackerOne

– Security Inbox for company

– 70+ Public Programs

– $1.9M Paid

• Synack

• CrowdCurity

Page 18: Bug bounty cash for hack

How to start with BugBounties

• Theory OWASP Top 10 WASC 26 Classes

• Practical's SVWA (Suruji Vulnerable Web Application) OWASP Mutillidae DVWA Hack.me

• Read Blog Post

• Follow Some researchers on Twitter

Page 19: Bug bounty cash for hack

http://h1.nobbd.de/

Page 20: Bug bounty cash for hack

Key Points

Page 21: Bug bounty cash for hack
Page 22: Bug bounty cash for hack

Ninja Skills? No Way!!!!

Page 23: Bug bounty cash for hack

Common Bugs

• Xss

• CSRF (Cross Site Request Forgery)

• Business Logical

• Insecure Direct Object References

• ClickJacking

• Session Management and BruteForce

• 0 Day CMS Vulnerabilities

Page 24: Bug bounty cash for hack

• BurpSuite (http://portswigger.net/)

• Google,Bing,Yahoo (Google Dorks)

• Mozilla Addons

Tampar Data

HackBar

Live HTTP Headers

User Agent Switcher

Page 25: Bug bounty cash for hack

Reporting and Bug Submission

• Make Standard format

Vulnerability Name

Domain

Vulnerable Subdomain

Infected URL

POC (Proof Of Concept)

Browser / Operating System

Description

Page 26: Bug bounty cash for hack

My Experience

Page 27: Bug bounty cash for hack

https://hackerone.com/reports/41409

Page 28: Bug bounty cash for hack

Any Questions?