What is the Bug Bounty Program?
Bug Bounty program provides recognition and compensation to security researchers practising responsible disclosure. Company started Bug Bounty programs for improve their security, Cyber security researchers are finding vulnerabilities on top websites and get rewarded.
Reward Programs
AT&T – http://developer.att.com/developer/apiDetailPage.jsp?passedItemId=10700235
(To submit you need to sign up to the free Developer API program)Avast! – http://www.avast.com/bug-bountyBarracuda – http://barracudalabs.com/Coinbase – https://coinbase.com/whitehatChromium Project – http://www.chromium.org/CrowdShield – https://crowdshield.com/Cryptocat – https://crypto.cat/bughunt/Facebook – http://www.facebook.com/whitehat/Etsy – http://www.etsy.com/help/article/2463Gallery – http://codex.gallery2.org/BountiesGhostscript – http://ghostscript.com/Bug_bounty_program.html (Mostly software development, occasional security issues)Google – http://www.google.com/about/company/rewardprogram.htmlHex-Rays – http://www.hex-rays.com/bugbounty.shtmlIntegraXor (SCADA) – http://www.integraxor.com/blog/integraxor-hmi-scada-bug-bounty-programLaunchKey – https://launchkey.com/docs/whitehatMarktplaats – http://statisch.marktplaats.nl/help/Mega.co.nz – http://thenextweb.com/insider/2013/02/01/kim-dotcom-puts-up-13500-bounty-for-first-person-to-break-megas-security-system/Meraki – http://www.meraki.com/trust/#srpMicrosoft – http://www.microsoft.com/security/msrc/reportMozilla – http://www.mozilla.org/security/bug-bounty.htmlPaypal – https://www.paypal.com/us/webapps/mpp/security/reporting-security-issuesPikaPay – https://www.pikapay.com/pikapay-security-policy/Piwik – http://piwik.org/security/Ricebridge – http://www.ricebridge.com/bugs.htm (Only available to customers)Ripple – https://ripple.com/bug-bounty/Samsung – https://samsungtvbounty.com/Simple – https://www.simple.com/policies/website-security/Tarsnap – https://www.tarsnap.com/bugbounty.htmlQiwi – https://www.qiwi.ru/page/hack.actionQmail – http://cr.yp.to/djbdns/guarantee.htmlYandex – http://company.yandex.com/security/index.xmlZerobrane – http://notebook.kulchenko.com/zerobrane/zerobrane-studio-bug-bounty
Product & Services (Hall Of Fame Only)
Acquia – https://www.acquia.com/how-report-security-issueActiveProspect – http://activeprospect.com/activeprospect-security/Adobe – http://www.adobe.com/support/security/alertus.htmlAmazon.com (retail) – please email details to security@amazon.comAndroid Free Apps – http://www.androidfreeapp.net/security-researcher-acknowledgments/Apple – http://support.apple.com/kb/HT1318Blackberry – http://us.blackberry.com/business/topics/security/incident-response-team/collaborations.htmlBraintree – https://www.braintreepayments.com/developers/disclosureCard – https://www.card.com/responsible-disclosure-policycPaperless – http://www.cpaperless.com/securitystatement.aspxChargify – https://chargify.com/security/DiMartino Entertainment – http://moosikay.dimartinoentertainment.com/site/credits/eBay – http://pages.ebay.com/securitycenterEVE – http://community.eveonline.com/devblog.asp?a=blog&nbid=2384Evernote – http://evernote.com/security/Foursquare – https://foursquare.com/about/securityFreelancer – http://www.freelancer.com/info/vulnerability-submission.phpFuture Of Enforcement – http://futureofenforcement.com/?page_id=695Gitlab – http://blog.gitlab.com/responsible-disclosure-policy/Gliph – https://gli.ph/s/security.htmlHakSecurity – http://haksecurity.com/special-thanks/Harmony – http://get.harmonyapp.com/security/Heroku – https://www.heroku.com/policy/security-hall-of-fameIconfinder – http://support.iconfinder.com/customer/portal/articles/1217282-responsible-disclosure-of-security-vulnerabilitiesKaneva – http://docs.kaneva.com/mediawiki/index.php/Bug_BountyKayako – https://my.kayako.com/Lastpass – https://lastpass.com/support_security.phpMahara – https://wiki.mahara.org/index.phpMailChimp – http://mailchimp.com/about/security-response/Microsoft (Online Services) – http://technet.microsoft.com/en-us/security/cc308589Netflix – http://support.netflix.com/en/node/6657#gsc.tab=0Nokia – http://www.nokia.com/global/security/acknowledgements/Nokia Siemens Networks – http://www.nokiasiemensnetworks.com/about-us/responsible-disclosureNorada – http://norada.com/crm-software/security_responseOwncloud – http://owncloud.org/about/security/hall-of-fame/Opera – https://bugs.opera.com/wizarddesktop/Oracle – http://:oracle.com/technetwork/topics/securityPuppet Labs – https://puppetlabs.com/security/acknowledgments/RedHat – https://access.redhat.com/knowledge/articles/66234Risk.io – https://www.risk.io/securitySecurity Net – http://www.securitynet.org/security-researcher-acknoledgments/Sellfy – https://sellfy.com/security/Spotify – https://www.spotify.com/us/about-us/contact/report-security-issues/Sprout Social – http://sproutsocial.com/responsible-disclosure-policyTelekom – http://www.telekom.com/corporate-responsibility/security/186450Thingomatic – http://thingomatic.org/security.html37signals – https://37signals.com/security-responseTuenti – http://corporate.tuenti.com/en/dev/hall-of-fameTwilio – https://www.twilio.com/docs/security/disclosureTwitter – https://twitter.com/about/securityWizeHive – http://www.wizehive.com/special_thanks.htmlXmarks – https://buy.xmarks.com/security.phpZendesk – http://www.zendesk.com/company/responsible-disclosure-policyZynga – http://company.zynga.com/security/whitehats
Product & Services (No Reward)
Amazon Web Services (AWS) – http://aws.amazon.com/security/vulnerability-reportingApriva – http://www.apriva.com/securityAuthy – https://www.authy.com/security-issueBlackboard – http://www.blackboard.com/footer/security-policy.aspxBox – https://www.box.com/about-us/security/Cisco – http://www.cisco.com/en/US/products/products_security_vulnerability_policy.htmlCloudnetz – http://cloudnetz.com/Legal/vulnerability-testing-policy.htmlContant Contact – http://www.constantcontact.com/about-constant-contact/security/report-vulnerability.jspCoupa – http://trust.coupa.com/home/security/coupa-vulnerability-reporting-policyDrupal – https://drupal.org/security-teamEMC2 – http://www.emc.com/contact-us/contact/product-security-response-center.htmEmptrust – http://www.emptrust.com/Security.aspxHeroku – https://www.heroku.com/policy/security-hall-of-fameHTC – http://www.htc.com/us/terms/product-security/Huawei – http://www.huawei.com/en/security/psirt/report-vulnerabilities/index.htmIBM – http://www-03.ibm.com/security/secure-engineering/report.htmlKPN – http://www.kpn.com/Privacy.htm#tabcontent3Lievensberg Hospital – http://www.lievensbergziekenhuis.nl/paginas/141-disclaimer.htmlLinkedIn – http://help.linkedin.com/app/answers/detail/a_id/37022Lookout – https://www.lookout.com/responsible-disclosureMillsap Independent School District – http://www.millsapisd.net/BugReport.cfmModus CSR – http://www.moduscsr.com/security_statement.phpPagerDuty – http://www.pagerduty.com/security/disclosure/Panzura – http://panzura.com/support/panzura-security-policy/Pidgin – http://pidgin.im/security/Plone – http://plone.org/products/plone/security/advisoriesPop Group – http://www.popgroupglobal.com/security.phpReddit – http://code.reddit.com/wiki/help/whitehatRelaso – http://relaso.com/disclosureSalesforce – http://www.salesforce.com/company/privacy/security.jsp#vulnerabilitySimplify – http://simplify-llc.com/simplify-security.htmlSkoodat – http://www.skoodat.com/securityScorpion Software – http://www.scorpionsoft.com/company/disclosurepolicy/Square – https://squareup.com/security/levelsSymantec – http://www.symantec.com/security/Team Unify – http://www.teamunify.com/__corp__/security.phpTele2 – http://www.tele2.nl/klantenservice/veiligheid/tele2-en-veiligheid.htmlT-Mobile (Netherlands) – http://www.t-mobile.nl/Global/media/pdf/privacy_statement_juni_2012.pdfUPC – http://www.upc.nl/internet/veilig_internet/beveiligingsproblemen/Viadeo – http://www.viadeo.com/aide/security/Vodafone (Netherlands) – http://over.vodafone.nl/vodafone-nederland/privacy-veiligheid/beveiliging-en-bescherming/wat-doet-vodafone/meld-een-beveiligVSR – http://www.vsecurity.com/company/disclosureX.commerce – http://www.x.com/securityXen – http://www.xen.org/projects/security_vulnerability_process.htmlZiggo – https://www.ziggo.nl/#klantenservice/internet/risicos-op-internet/meldpunt-beveiligingslekken
Comments
Post a Comment