- Hands-On Bug Hunting for Penetration Testers
- Joseph Marshall
- 151字
- 2021-07-16 17:53:04
Company-Sponsored Initiatives
Company-sponsored programs are just what they sound like. It's not just large mega-corps that have bounty programs – a surprising number of businesses have a process for rewarding security contributions. The size of each company can drastically effect the requirements and conditions for a reward: large companies pay top dollar for vulnerabilities, but the low-hanging fruit of those flaws will already have been picked; start-ups will have less mature applications, but probably a smaller application attack surface, assembled from a newer stack with fewer known vulnerabilities, and might want to pay for contributions in swag. Companies that are mature enough to suffer from technical debt, but also have a budget to pay rewards, are a nice fit. Sometimes, though, you'll just have to poke around in different areas, taking your chances, to find your next vulnerability.
Here are some examples of the programs offered by larger companies.
- API安全實(shí)戰(zhàn)
- 工業(yè)互聯(lián)網(wǎng)安全防護(hù)與展望
- Getting Started with FortiGate
- Digital Forensics with Kali Linux
- API安全技術(shù)與實(shí)戰(zhàn)
- Advanced Penetration Testing for Highly:Secured Environments(Second Edition)
- Kerberos域網(wǎng)絡(luò)安全從入門(mén)到精通
- CTF那些事兒
- 實(shí)用黑客攻防技術(shù)
- 數(shù)字政府網(wǎng)絡(luò)安全合規(guī)性建設(shè)指南:密碼應(yīng)用與數(shù)據(jù)安全
- 網(wǎng)絡(luò)空間安全導(dǎo)論
- 物聯(lián)網(wǎng)信息安全技術(shù)
- 黑客攻防從入門(mén)到精通:命令版
- Kali Linux無(wú)線網(wǎng)絡(luò)滲透測(cè)試詳解
- Metasploit 5.0 for Beginners