- Hands-On Bug Hunting for Penetration Testers
- Joseph Marshall
- 148字
- 2021-07-16 17:53:05
Facebook has a bug bounty program with a minimum payout of $500, but as the very direct language in their responsible disclosure policy attests, they do not tolerate mucking about with production data: if you comply with the policies when reporting a security issue to Facebook, they will not initiate a lawsuit or law enforcement investigation against you in response to your report.
The amount of information available for their program is minimal. You'll find a side-by-side example of a submission report and an improved version, with some non-qualifying vulnerabilities, but not much in the way of universal lessons or professional tips.
As the legalese signals, Facebook is very sensitive to misuse of its platform – especially given recent increased scrutiny. And because so many exploits will be aimed at affecting users, it's critical to stop short of writing any code that could subvert an account.
- INSTANT Metasploit Starter
- 電子支付的規(guī)制結(jié)構(gòu)配置研究
- 工業(yè)物聯(lián)網(wǎng)安全
- 移動APT:威脅情報分析與數(shù)據(jù)防護
- 網(wǎng)絡(luò)空間安全實驗
- 學(xué)電腦安全與病毒防范
- 情報驅(qū)動應(yīng)急響應(yīng)
- 華為Anti-DDoS技術(shù)漫談
- 黑客攻擊與防范實戰(zhàn)從入門到精通
- 網(wǎng)絡(luò)空間安全實戰(zhàn)基礎(chǔ)
- Kali Linux無線網(wǎng)絡(luò)滲透測試詳解
- Instant OSSEC Host-based Intrusion Detection System
- 一本書講透混合云安全
- 數(shù)據(jù)安全實踐:能力體系、產(chǎn)品實現(xiàn)與解決方案
- 網(wǎng)絡(luò)安全攻防技術(shù)實戰(zhàn)