So I recently became aware that many major technology companies have active reward systems in place for responsible disclosure of bugs and potential security vulnerabilities. While I'm familiar with the idea, I didn't realize there was a website which conveniently lists active programs and whether or not the company is offering bounties / rewards.
https://bugcrowd.com/list-of-bug-bounty-programs
More notable participants include (not an exhaustive list):
Dropbox
Github
Google
Facebook
Microsoft
Mozilla
Paypal
Tesla
Twitter
YouTube
For example, Google is paying bounties ranging from $500 - $60,000 to anyone who reports a vulnerability in Chromium which they deem serious enough to warrant a reward.
If you're interested in security research as a hobby but aren't interested in the prison time associated with irresponsible targeting, perhaps you should consider targeting one of these companies instead.
Legal Hacking (Bug Bounty)
Moderator: Geeks United
- dandymcgee
- ES Beta Backer
- Posts: 4709
- Joined: Tue Apr 29, 2008 3:24 pm
- Current Project: https://github.com/dbechrd/RicoTech
- Favorite Gaming Platforms: NES, Sega Genesis, PS2, PC
- Programming Language of Choice: C
- Location: San Francisco
- Contact:
Legal Hacking (Bug Bounty)
Falco Girgis wrote:It is imperative that I can broadcast my narcissistic commit strings to the Twitter! Tweet Tweet, bitches!
- Accy
- Chaos Rift Newbie
- Posts: 29
- Joined: Tue Jan 28, 2014 11:10 am
- Programming Language of Choice: C++
- Location: USA
Re: Legal Hacking (Bug Bounty)
The US military also hires people to maliciously hack other countries if you're into that. Though I don't know how many hackers want to be a SLAVE TO THA MASHEEN
- dandymcgee
- ES Beta Backer
- Posts: 4709
- Joined: Tue Apr 29, 2008 3:24 pm
- Current Project: https://github.com/dbechrd/RicoTech
- Favorite Gaming Platforms: NES, Sega Genesis, PS2, PC
- Programming Language of Choice: C
- Location: San Francisco
- Contact:
Re: Legal Hacking (Bug Bounty)
Yeahhhh, no. I would probably end up being the next Snowden.Accy wrote:The US military also hires people to maliciously hack other countries if you're into that. Though I don't know how many hackers want to be a SLAVE TO THA MASHEEN
Falco Girgis wrote:It is imperative that I can broadcast my narcissistic commit strings to the Twitter! Tweet Tweet, bitches!