Bug Bounty 101
Shahee Mirza
About Me
System Security Engineer at Tasawr Interactive
Security Researcher
OWASP contributor
Bug Bounty Hunter
FB: http://fb.me/shahee.mirza.5
Twitter: @shaheemirza
WEB: http://www.shaheemirza.com
What is Bug Bounty?
Bug bounties, also known as responsible disclosure
programmes, are setup by companies to encourage
people to report potential issues discovered on their
sites. Some companies chose to reward a researcher
with money, swag, or an entry in their hall-of-fame. If
you’re interested in web application security then
they’re a great way of honing your skills, with the
potential of earning some money and/or credibility at
the same time.
History of Bug Bounty
At October 1995 by Netscape.
At August 2002 by iDefense [VCP].
At August 2004 by Mozilla.
2007 CanSecWest……ZDI…$10k..
March 24, 2010…pwn2own..big money.
Days before 2008 was Tough for Security
Researchers.
2009, the year of revolution.
Vendor Response
Then ..Our Response
Now…… :p
Why bug bounties ?
For us
Values of your Resume.
Increase Possibility of getting a job in the
industry.
Opportunity to make money on spare time.
Glory and Fame.
 Knowledge.
 The proven one.
For Vendors
Less Hacks and Breaches.
Better and more secure apps or services.
Faster security implementation.
More researchers.
More experience.
More bugs.
My favorite programs !!
GOOGLE
– Min $1337
– Acquisitions’ min: $100
– Max.: $20,000
URL:
http://www.google.com.bd/about/appsecurity/reward-program/
FACEBOOK
– Min.: $500
– Max. payout: …………
URL: https://www.facebook.com/whitehat
MORE
https://bugcrowd.com/list-of-bug-bounty-programs
My favorite platforms !!
BugCrowd
URL: https://bugcrowd.com/
HackerOne
URL: https://hackerone.com/
..and
URL: https://www.synack.com/
URL: https://www.crowdcurity.com/
READY !!
Lesson 000
Patience – The Patience
Lesson 001
Avoid – OS Arguments.
Avoid – Browser Arguments.
Avoid – Language Arguments.
Lesson 010
Do not use automated scanners:
- Acunetix
- Nikto
- Etc
Learn to Code
- Python
- PHP
- Etc
Lesson 011
TOOLS:
Lesson 011 cont.
URL:
Burp Suite - http://portswigger.net/burp/
ZAP - https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project
Nmap - http://nmap.org/
DNS-Discovery - http://dns-discovery.googlecode.com
Fierce - http://ha.ckers.org/fierce/
Lesson 100
Self Practice ground:
URL: http://www.dvwa.co.uk/
Lesson 100 cont.
Self Education:
Attack:
https://www.owasp.org/index.php/Category:Attack
Code Snippet:
https://www.owasp.org/index.php/Category:Code_Snippet
Control:
https://www.owasp.org/index.php/Category:Control
Vulnerability:
https://www.owasp.org/index.php/Category:Vulnerability
Lesson 101
The Base and Basics:
Read the Rules of programs.
Read the Scope and Limits.
Read the Payment scheme and Methods.
Read, how to get a test account.
Respect the Panel Decisions.
Lesson 101 cont.
Please DO NOT:
Don’t be a Shit.
Don’t Lie.
Don’t cry for SWAG /Money /HOF if it’s out of rules.
Don’t disrespect other researchers.
Don’t Copy-Paste from other reports.
Please, Don’t share your payouts. [amounts]
Lesson 101 cont.
Quality > Quantity
Quality ==> Reputation ==> Opportunities
Lesson 101 cont.
Be very Sharp and Clear on Issue description.
Steps to reproduce the issue
Impact
Attach screenshot(s) if needed.
If you recorded any video:
- Don’t use music.
- Make it quick.
- Use Mp4 or Flv format.
How to write Report:
Bad Report
Lesson 101 cont.
GOOGLE for us:
URL:
https://sites.google.com/site/bughunteruniversity/
Lesson 101 cont.
Bugs on Fire:
URL: http://osvdb.org/
Lesson 101 cont.
Just a demo:
Rate limiting bypass
Lesson 101 cont.
Public Disclosure:
Ask for permission.
Hide sensitive information.
Future of Bug Bounties:
More companies, More bounty.
More money, More opportunities.
Bangladeshi Hackers on Bug Bounty
…………………………We are everywhere
Google <> Facebook <> Twitter
Microsoft <> PayPal <> GitHub
When I was Alone
I love to dance:
When rest of all came
I love to dance with them:
Thank you buddies:
Tarek Siddiki
Faisal Ahmed
Md. Ishrat Shahriyar
Abdullah Shahriar
…………..and rest of all
Helpful Books
Helpful Blogs
http://www.breaksec.com/
http://homakov.blogspot.co.uk/
https://bitquark.co.uk/blog/
https://nealpoole.com/blog/
http://nahamsec.com/
http://stephensclafani.com/
http://insertco.in/articles
http://josipfranjkovic.blogspot.co.uk/
http://olivierbeg.nl/
https://fin1te.net/
THANK YOU ALL

Bug Bounty 101