Mise en place d'un programme de Bug Bounty

16
BUG BOUNTY PROGRAM PRESENTATION & FEEDBACK

Transcript of Mise en place d'un programme de Bug Bounty

Page 1: Mise en place d'un programme de Bug Bounty

BUG BOUNTY PROGRAMPRESENTATION & FEEDBACK

Page 2: Mise en place d'un programme de Bug Bounty
Page 3: Mise en place d'un programme de Bug Bounty

WHAT’S A BUG BOUNTY▸Deal for reporting bugs and security leaks

▸First appeared in 1995

▸Google: 2010

▸Rest of the world: 2011

▸No more consultants, audits, blah blah

PRESENTATION

Page 4: Mise en place d'un programme de Bug Bounty
Page 5: Mise en place d'un programme de Bug Bounty

HACK YOURSELF BEFORE OTHERS DO

PRESENTATION

Page 6: Mise en place d'un programme de Bug Bounty

ADVANTAGES▸Cheap

▸Pay as you go

▸Distributed

▸Transparency

▸Experts

PRESENTATION

Page 7: Mise en place d'un programme de Bug Bounty

DRAWBACKS

▸Bandwidth

▸Reactivity

▸Trust

PRESENTATION

Page 8: Mise en place d'un programme de Bug Bounty

FEEDBACK

HUNTER.IO▸Distributed team of 5

▸No security expert

▸Focused on UX and data quality, not on security

Page 9: Mise en place d'un programme de Bug Bounty

FEEDBACK

ANNOUNCEMENT

Page 10: Mise en place d'un programme de Bug Bounty

FEEDBACK

ANNOUNCEMENT▸Rules (do not disturb, no automation, test

with your own data, don’t publish until we fixed, etc.)

▸Rewards

▸What’s included and what’s not

▸How to report

Page 11: Mise en place d'un programme de Bug Bounty

FEEDBACK

RESULTS

Page 12: Mise en place d'un programme de Bug Bounty

FEEDBACK

RESULTS▸> 30 reports

▸7 rewards

▸About 2000$ bounties

▸A few disappointed hackers

▸A tested and retested app by dozens of hackers

Page 13: Mise en place d'un programme de Bug Bounty
Page 14: Mise en place d'un programme de Bug Bounty

FEEDBACK

KEY SUCCESS FACTORS▸Be reactive

▸Be generous

▸Be kind

▸Be transparent

▸Be confiant

Page 15: Mise en place d'un programme de Bug Bounty

FEEDBACK

SOURCES▸https://hackerone.com/

▸https://bountyfactory.io

▸https://internetbugbounty.org/

Page 16: Mise en place d'un programme de Bug Bounty

QUESTIONS?

[email protected]

THANK YOU