- Hands-On Bug Hunting for Penetration Testers
- Joseph Marshall
- 152字
- 2021-07-16 17:53:05
GitHub
GitHub offers a bounty program that covers a wide array of its properties, including the API, enterprise app, and main rails site (https://github.com/), with payouts ranging from $555 to $20,000 for most of those targets.
One neat feature of the GitHub program is that each participant who successfully submits a bounty receives a profile page that – in addition to showing the points they've accumulated, rank, and earned badges – lists their reported vulnerabilities with a short technical blurb about each one. Like the published submission reports on other platforms, any technical detail about a successfully-discovered vulnerability is an invaluable insight into winning strategies, both in general and for the site in question.
And if you're looking to parlay finding bugs into a larger career in security, profile pages such as the ones offered by GitHub, Bugcrowd, and HackerOne can be great bullet points on your resume.
- Web漏洞分析與防范實(shí)戰(zhàn):卷1
- Metasploit Penetration Testing Cookbook(Second Edition)
- 為你護(hù)航:網(wǎng)絡(luò)空間安全科普讀本(第2版)
- INSTANT Metasploit Starter
- API攻防:Web API安全指南
- 網(wǎng)絡(luò)安全技術(shù)與實(shí)訓(xùn)(第4版)(微課版)
- 從0到1:CTFer成長(zhǎng)之路
- 信息安全等級(jí)保護(hù)測(cè)評(píng)與整改指導(dǎo)手冊(cè)
- 互聯(lián)網(wǎng)企業(yè)安全高級(jí)指南
- 數(shù)據(jù)保護(hù):工作負(fù)載的可恢復(fù)性
- 網(wǎng)絡(luò)安全態(tài)勢(shì)感知
- 實(shí)用黑客攻防技術(shù)
- 捍衛(wèi)隱私
- 隱私保護(hù)機(jī)器學(xué)習(xí)
- INSTANT Microsoft Forefront UAG Mobile Configuration Starter