Bug Bounty - Hackers Job

12
Bug Bounty - Hackers Job Arbin Godar (@arbingodar)

Transcript of Bug Bounty - Hackers Job

Page 1: Bug Bounty - Hackers Job

Bug Bounty - Hackers Job

Arbin Godar (@arbingodar)

Page 2: Bug Bounty - Hackers Job

Arbin Godar #whoami

- Student @ Trinity International College- Guy interested in web security- A mediocre programmer, hobbyist etc.

Page 3: Bug Bounty - Hackers Job

Acknowledged by

etc….

Page 4: Bug Bounty - Hackers Job

What is Bug Bounty?Paying monetary reward to security researchers for certain qualifying security bugs.

Hacker find security bug and reported bug on Example

Example security team triaged the bug

Example pays $$$ according to it’s impact

Page 5: Bug Bounty - Hackers Job

Why companies run bug bounty program?

- Fastest way to improve security publicly- Safety- Cost effective

Page 6: Bug Bounty - Hackers Job

Why bug hunting?

- To make money- To have fun- To build strong portfolio - To be challenged etc.

Page 8: Bug Bounty - Hackers Job

How to start bug hunting ?

- Practice makes a man perfect- Reading : books , proof of concepts - Requires little programming knowledge- Think logically

Page 9: Bug Bounty - Hackers Job

Popular bug bounty programs and platforms

- Facebook, Google, Twitter, Yahoo, PayPal etc.

- Platforms: HackerOne , Bugcrowd, Cobalt, Synack etc.

Page 10: Bug Bounty - Hackers Job

Submitting Bug Report

- Title - Description of bug- Step to Reproduce the bug- Impact- Suggested Fix

Page 11: Bug Bounty - Hackers Job

For Motivation

Page 12: Bug Bounty - Hackers Job

Thank You!

Arbin Godar (@arbingodar)[email protected]