Showing posts with label HackerOne. Show all posts
Showing posts with label HackerOne. Show all posts

Thursday, 25 June 2015

HackerOne Receives Investment Of $ 25 Million


HackerOne, the platform for reporting vulnerabilities in various software projects and applications, during a new round of investment $ 25 million received. HackerOne was in 2013 founded with the help of Facebook and Microsoft. Initially HackerOne focused on rewarding bug reports in popular software projects from which millions of people use. Meanwhile, all kinds of software companies through the website launched a so-called "bug bounty program."

HackerOne fulfills coordination between bug detector and the software in question. Also advises the platform software vendors for their own software via HackerOne want to start a rewards program. The money in the latest round of investment was raised include from Salesforce Chairman and CEO Marc Benioff, Dropbox's CEO and co-founder Drew Houston and Yelp CEO and co-founder Jeremy Stoppelman.

Since the last round of investment HackerOne the number of employees has expanded from 10 to 50. By now, Yahoo !, Twitter, Adobe, Dropbox, LinkedIn, Snap Chat and Airbnb all use the services of the platform. The total number of customers has now passed the 250. These software companies and projects in recent years to more than 1,500 researchers over $ 3.2 million was paid. The money was used to locate nearly 10,000 vulnerabilities and fix. Despite the positive noises made ​​LinkedIn recently announced that it had started a private reward program for a select group of researchers, because programs where everyone can join would create too much noise to. Why chose LinkedIn sure to route payments to researchers via HackerOne.

Friday, 19 June 2015

LinkedIn Pays Select Group Of Investigators For Leak



The business social networking site LinkedIn has since late last year decided to reward a program for a select group of researchers who report vulnerabilities. Unlike many other sites that launched a reward program to open bug reports LinkedIn decided the program decided to keep. According to information director Cory Scott , the program stems from the bug reports via security@linkedin.com enter.

Most reports were not usable according to Scott, but a small group of researchers used to send detailed bug reports. Then LinkedIn for this group of researchers decided to launch a special rewards program. This has already yielded more than 65 specific bugs for which more than $ 65,000 was paid. The program is structured so that the security team LinkedIn directly with investigators from the beginning works to the end. Payments late LinkedIn HackerOne walk through a platform where many companies start public reward programs.

Scott notes that LinkedIn has looked at an open reward program, but given the experience of external bug reports and the status of the current ecosystem of bug reports, the cost does not outweigh the benefits. Yet Scott calls outside researchers for bugs via security@linkedin.com to continue to report. He further states that it was decided to share the experiences LinkedIn to give "more nuance" to the discussion on the subject, which might be useful for others.

Friday, 17 April 2015

Dropbox Will Pay Hackers To Bug Reports



The popular online storage service Dropbox goes hackers and researchers now have to pay for reporting bugs. In a blog posting suggests Devdatta Akhawe Dropbox storage service that sorts itself enable experts to find security problems, but that it can use all the help security researchers. The payment of bug rewards is an important incentive, set Akhawe.

Dropbox has also received all kinds of bug reports in the past and will reward all these researchers retrospectively. This is an amount totaling $ 10,475. The reward program Dropbox is organized through HackerOne , an initiative that offers companies the opportunity to start so-called "bug bounty" programs.

Approved bug reports can count on a minimum fee of $ 216, the maximum amount has not been established. The highest reward that Dropbox has so far paid amounts to nearly $ 5,000. According Akhawe late offering a reward program to see how dedicated Dropbox to privacy and security. Since the launch of the program, there are already 27 reported bugs and thanks 26 hackers.

Monday, 30 March 2015

Indian Student Pays Training With Bug Reports


The search for vulnerabilities in applications, web applications and other software for many researchers now become a lucrative business, with an Indian student pays even trained with. Shashank Kumar, known on Twitter as cyberboyIndia would now have about $ 30,000 in bug reports are earned. Thus he was able to pay most of his training, so he lets opposite The Verge know.

Despite the revenue say many researchers working on so-called "bug bounty" join programs that they are not full-time to look for vulnerabilities, but rather a part-time job or a way to generate additional income. Earnings that are higher on the black market. Nevertheless, most hackers would choose an official reward program, says Alex Rice, former security chief on Facebook and now CTO of HackerOne.

"In order to sell something on the black market you should make one weapon. That could take months," said Rice. Most hackers do have the skills, according to him, but no bad intentions. Yet it also happens that hackers find that they did not have enough money or that bugs are not resolved quickly enough. Often these hackers then decide to reveal the problem yet, what a PR nightmare for businesses can be said Gus Anagnos of SYNACK.

That can ensure that companies in each bug melding overreact. "As an organization wasting a gun to his head, the start time to vulnerabilities that are not very important," Anagnos notes. There are also now several platforms launched where companies can join. The platform receives the entries and make the selection and communication, so the company only receives structured bug reports, so that can be solved earlier.

Tuesday, 10 February 2015

HackerOne Bug Fixes Serious Platform For Bug Reports


HackerOne, the platform for reporting vulnerabilities in various software projects and applications, has itself had to deal with a serious vulnerability that attackers may have access to unpublished bug reports from other investigators could get.

Cross Site Scripting (XSS) issue exists was caused by the way HackerOne the "\" character tried left harmless. Therefore could allow an attacker to execute code on a webpage, which could help again in a phishing attack, says researcher Daniel LeCheminant who discovered the problem.

He suspects that an attacker could also add arbitrary HTML to bug reports in order to gain unauthorized access to the bug reports and data from other researchers. It is the first time that an XSS problem was discovered in HackerOne. A day after LeCheminant administrators had informed the vulnerability was corrected and he got a reward of $ 5,000. An amount that is only for serious bugs reserved .