官术网_书友最值得收藏!

HackerOne

HackerOne (https://www.hackerone.com/) is a similar platform – it has its own point system (reputation) and also calculates a variety of metrics that it uses as the basis for its Leaderboard and for invitations to its own private programs.

Like Bugcrowd, it also has a bug bounty policy for itself – if you find a vulnerability in one of its sites or apps, you're entitled to a reward. Interestingly though, you might still be entitled to a reward even if you don't discover a bug. From their site:


"HackerOne is interested in your research on our systems, regardless of whether you found a security vulnerability. If you have found yourself looking at a particular feature on one of our assets but didn't find anything, please submit a report that describes all the different things you tried and failed. We may reward you for substantial research performed on assets under our bug bounty policy."

This is an usual policy that still makes sense: providing a detailed list of everything that worked is its own audit of the company's resources, even if it doesn't cover any vulnerable areas.

HackerOne and Bugcrowd both have a similar breadth of different companies, with different products, business models, and security needs. HackerOne does have a few notable companies that are exclusive to its platform, most notably Twitter, but generally the offerings are very similar.

主站蜘蛛池模板: 大悟县| 东城区| 堆龙德庆县| 凤翔县| 应用必备| 苏州市| 饶阳县| 岳普湖县| 板桥市| 道孚县| 湄潭县| 贵州省| 军事| 乌拉特中旗| 宝山区| 巫溪县| 南木林县| 安国市| 永州市| 莒南县| 含山县| 双城市| 屯昌县| 台东县| 杭锦后旗| 桂阳县| 灵山县| 长岭县| 当涂县| 新建县| 玛沁县| 田阳县| 大英县| 苍梧县| 营口市| 黔南| 军事| 石河子市| 巴楚县| 黄梅县| 泸州市|