Home Blog Page 380

After US, now UK proposes ban on Kaspersky Labs products

Kaspersky

Seems like bad luck Brian is not going to leave Moscow-based cybersecurity firm Kaspersky Labs anytime soon. After the clamor at the United States Senate and the following ban in the nation, Britain’s cybersecurity agency has warned government departments to refrain from using antivirus software from Kaspersky Labs citing concerns over the company’s ties to the Kremlin and Russian spy operations.

In a letter addressed to the head honchos of several civil service departments, Ciaran Martin, head of the National Cyber Security Centre has stated that, “The specific country we are highlighting in this package of guidance is Russia.  As the Prime Minister’s Guildhall speech set out, Russia is acting against the UK’s national interest in cyberspace. The NCSC advises that Russia is a highly capable cyber threat actor which uses cyber as a tool of statecraft. This includes espionage, disruption and influence operations. Russia has the intent to target UK central Government and the UK’s critical national infrastructure.”

According to him, the overwhelming majority of UK individuals and organizations, “are far more likely to be targeted by cyber criminals.” But the best of the interests, “we advise that where it is assessed that access to the information by the Russian state would be a risk to national security, a Russia-based AV (anti-virus) company should not be chosen.”

Earlier this year, U.S. Senator Jeanne Shaheen had pressed for a federal government-wide ban of all Kaspersky Lab products in U.S. Shaheen cited that intelligence officials during a public hearing had stated that they weren’t comfortable with using Kaspersky Lab software in computers at the intelligence agencies. Adding, “Americans were outraged by Russia’s interference in our presidential election, but a wider threat is Russia’s doctrine of hybrid warfare, which includes cybersabotage of critical American infrastructure from nuclear plants to electrical grids. Kaspersky Lab, with an active presence in millions of computer systems in the United States, is capable of playing a powerful role in such an assault. It’s time to put a stop to this threat to our national security.”

Following which, Kaspersky Labs admitted taking inactive files in pursuit of hackers. While claiming that “we did nothing wrong”, Eugene Kaspersky in an interview said “the files containing the National Security Agency (NSA) hacking tools were taken because they were part of a larger file that included suspicious software, a tool researchers dubbed GrayFish. Such actions occur only in very, very, very rare cases.”

Managed security services market to grow at CAGR of 14.7% between 2017-2025

Service Security Market

Globe Newswire: Research and Markets recently came up with the “Managed Security Services Market Outlook to 2025: Global Report” report. According to the report, the global managed security services market is estimated to grow at a CAGR of 14.7% during the forecast period 2017-2025 and accounts for US$ 18,030.9 Mn in the year 2025.

Increasing cyber threats across industries, digital transformation across industries, and increase in adoption of BYOD are fueling the growth of managed security services market. Majorly developing economies contribute a major portion of the market share to the managed security services market, where cybersecurity market both are growing at significantly higher pace, also the developed economies are anticipated to demand up-gradation and innovation in existing managed security services in the coming years.

The managed security services landscape is growing and evolving with innovative services to efficiently and proficiently secure the IT infrastructure of organization. Due to lack of skilled workforce, many organizations are not capable enough to fully protect their IT infrastructure. Moreover, increase in sophistication of cyber-attacks, it is becoming very challenging for organizations to rely and invest in their in-house security processes.

Hence, many organizations are migrating from their in-house security processes to third party MSSPs. MSSPs offer complete managed security services to organization with round the clock monitoring of organization’s IT infrastructure and preventing them from potential threats and cyber-attacks.

Present-day security processes demands a balance of device management, event monitoring, and incident response, as well as Governance, Risk, and Compliance functions. Increasing number of cyber-attacks and ever-growing complex risk and compliance requirement have led to the demand for third party specialize security service providers.

North America with the most advanced software and IT services organizations in the world contributes the largest market share in the global managed security services market. APAC with large number of emerging countries along with increasing numbers of smart cities and high FDI, is growing with the highest growth rate. Europe market stood at the second largest market for managed security services owing to increasing number of cross-border transactions. However, Middle East & Africa and South America market is still in the nascent stage of the market.

The report is available at: https://www.researchandmarkets.com/research/jl2d9x/managed_security

UK shipping firm Clarkson hacked

On November 29, 2017, Clarksons PLC, one of the largest shipping firms, reported a cyber attack and expressed fear that perpetrator(s) may release sensitive data and confidential information from company’s computer network soon.

In a statement, research consultant and logistical support firm Clarksons said, “As soon as it was discovered, Clarksons took immediate steps to respond to and manage the incident. Our initial investigations have shown the unauthorized access was gained via a single and isolated user account which has now been disabled. Clarksons would like to apologize to shareholders, clients and staff for any concerns this incident may raise.”

The London-based shipbroker company did not disclose the extent of the breach and said that it had reported the incident to the police to investigate the matter. To probe the matter, the company is in consultation with data security specialists and will soon begin the process of directly contacting affected clients and individuals.

Amid raised security concerns, the company has accelerated the roll-out of additional IT security measures and have put its legal team on standby to prevent the dissemination of confidential data. Shortly after the announcement, Clarksons’ shares fell by more than 2 percent.

Andi Case, the Clarksons CEO was quoted saying as to The Guardian, “Issues of cybersecurity are at the forefront of many business agendas in today’s digital and commercial landscape, and despite our extensive efforts we have suffered this criminal attack. As you would rightly expect, we’re working closely with specialist police teams and data security experts to do all we can to best understand the incident and what we can do to protect our clients now and in the future.”

Founded in 1852, Clarksons now operates in 21 countries. It is listed on the main market of the London Stock Exchange under the ticker CKN and is a member of the FTSE 250 Index.

Apple fixes bug in new version of Mac operating system within 24 hours

Apple Is Hackers’ Favorite for Brand Phishing Attacks, REvil gang threatens Apple blueprint leak

A day after a researcher discovered a huge login security flaw in the latest version of Apple’s macOS High Sierra operating system, the company said that it would review its software development process. On November 29, 2017, Apple said it released a patch to fix the password bug that would be automatically installed on the vulnerable machines. The bug reportedly enabled hackers to gain access to Apple computers without using a password.

The bug was discovered by a Turkish software developer, Lemi Orhan Ergin, who took to the micro-blogging site Twitter to report the issue. He tweeted “Dear @AppleSupport, we noticed a *HUGE* security issue at MacOS High Sierra. Anyone can login as “root” with empty password after clicking on login button several times. Are you aware of it @Apple?”

Ergin’s tweet went viral within no time and it got 12,744 retweets at the time of publishing this report. In an article on Medium.com, Ergin elaborated the story behind “anyone can login as root” tweet. He wrote “On Nov 23, the staff members informed Apple about it (bug issue). They also searched online and saw the issue mentioned in a few places already, even in Apple Developer Forum from Nov 13. It seemed like the issue had been revealed, but Apple had not noticed yet.”

With prompt action, Apple fixed the patch within 24 hours after security engineers learned of the bug issue on November 28, 2017, following Ergin’s tweet.

In a statement, the U.S. technology giant said, “We greatly regret this error and we apologize to all Mac users. Our customers deserve better. We are auditing our development processes to help prevent this from happening again. Security is a top priority for every Apple product, and regrettably we stumbled with this release of Mac OS”.

Immediately after the bug report was spread, the U.S. and German governments issued alerts advising Mac users to install the patch. In tech stocks, Apple stock was reported to be down to 2.6 percent at $168.55 on November 29, 2017.

Earlier this month, Apple was left red-faced when its newly launched iOs 11.1 and Safari were hacked several times by security researchers at a hacking competition called Pwn2Own in Tokyo.

2018 Predictions…Bugger that, let’s look at what we got right/wrong for 2017

2018

Contributed by Chris Roberts, Chief Security Architect, Acalvio Technologies

Just got asked to put the 2018 predictive hat on…BUT before I do that I want to look back at what I wrote for this year and take an objective (ish) look at how well I read the tea leaves 🙂

We will baseline with the following:

Wants:

  • Secure design, it is NOT too much to ask for, but it seems too much to be able to deliver. (Nothing changed here, STILL want this!)
  • Honest executives who stand up and take responsibility for being breached IMMEDIATELY. (Couple have, most have still hidden behind a veil of BS)
  • Those very same executives to actually take action BEYOND the first 6 months POST breach. (Yea, not happening here IS IT YAHOO/Etc.)
  • When sales or marketing want a new Cloud service…they actually INVOLVE IT/InfoSec. (Seen more of the collaboration here)
  • Threat intelligence that makes sense AND is usable in a timely manner. (Didn’t I build one?) (Nope, still a mess)
  • People to stop using 123456, Password1 and other bloody useless codes to defend their assets. (Nope, we are still password stupid)
  • Retail, financial, healthcare and other industries hit…when will someone p0wn the lawyers? (Lawyers starting to get hit w00t!!!)
  • Intelligent AI…actually something that works…although possibly I don’t want this? (Hmmm, this IS starting to make its presence felt….)
  • Something that actually stops me from moving away from the first computer we break into. (STILL working on this…)
  • A system my grandmother can use that REMAINS secure past the date of purchase. (Nope, still not there…)

Predictions:

  • All your toasters belong to…NOT YOU (same goes for your fridge, microwave and crockpot.) Oh yea, IoT hacks and BotIoTNets…got this one 🙂
  • Not only is your PC encrypted and ransomed, so is your NEST, Samsung TV, LG Fridge, etc. Ish, ransomware on IoT and portable still not there..damm!
  • We keep hearing that there are shortages in our field; we will continue to feel the negative effects. Yep, this one’s hurting AND will continue to do so…
  • 123456 become 124356, integrity of your data is questioned based on the undetected attacks. The concept of data integrity IS now an issue….yea!
  • All your IT is run by your business units. The cloud disseminates the IT’s ability to manage data. Yep, coming into its own as more and more of an issue…
  • All our data still doesn’t make sense…data analytics and modeling still has a long way to go. Arguably we still generate more data than we can comprehend?
  • Managed security services will continue to grow; all MY problems become YOURS (hopefully.) Yep, MORE and MORE getting into the VSOC world
  • The ability for LE around the globe to continue to collaborate on key issues WILL grow. Ish, need others to chime in here…
  • Blockchain and BitCoin get used to those two words…they will continue to evolve and grow. Yea, I win the buzzword bingo on this one!
  • The continued evolution of the attackers Swiss army knife of leased/purchased exploits avenues. Unfortunately yes, this one is a nasty reality…
  • The evolution of non-traditional security. The Stack we have doesn’t work, time for something new. STILL have a LOT to do before we kick reactive security out…
  • IF Amazon or anyone fully realizes drone delivery then watch drone-jacking become “a thing.” Dammit, still hoping this one comes true in 2018 😉

Thanks folks 🙂

2018’s list will be out soon-ish 🙂

This appeared as a LinkedIn article, and is published with Chris Robert’s permission.

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

10 things* (and a bonus one) about hackers…

BlackMatter ransomware

Contributed by Chris Roberts, Chief Security Architect, Acalvio Technologies

So, there’s the distinct possibility I might have gone on a recent rant about hackers and hoodies, masks, gloves and how the media stereotypes us AND how we’ve managed to do the same to ourselves thanks to some overzealous marketing departments. With all of that being said I thought I’d build off the involvement I had in Ellen’s piece in TheStreet’s on things people don’t know about those of us in this industry.

  1. Most of us do own hoodies, they are warm, versatile and comfortable to wear when out and about on physical penetration tests, HOWEVER, most of us don’t sit at the keyboard with the hood up, gloves on and our faces covered…lets adjust that particular stereotypes please.
  2. Many of us prefer black or darker colors…we travel a LOT, we are not always able to stay in the best of shapes and black works to hide the extra padding we’ve accumulated (temporarily in many cases…) let’s face it you don’t want a bunch of slightly chubby hackers breaking into your offices wearing fuchsia or orange do you?
  3. A LOT of us are self-taught, we have a thirst for knowledge that goes beyond just technical/traditional “geek” things…you’d be surprised if you engage us in conversation that we are typically well read, well versed AND articulate IF we could just work out how to converse with people sometimes 🙂
  4. We are not always the best at communication, we typically think in patterns that are different than most others, we too often ask people to move out of the way and just let us “fix it” as opposed to taking the time to help educate all around us…and unfortunately we don’t like explaining things multiple times…we have to do a better job of communication with others at the user, manager and executive level, and they in turn need to do a better job of listening…it’s a symbiotic relationship that both parties have to do a better job of understanding…we know it.
  5. Some of us will wear kilts a lot of the time; we wear them to conferences, to work, to meetings etc. Our community has no problem with kilts just as we have no problem with people identifying with ANYTHING they want to wear or BE. Whatever you want to wear, whatever or whoever you want to be IS acceptable in our community, the rest of the world needs to learn that lesson. HOWEVER, if you call my kilt a skirt I will hollow out your head with a spork and replace it with the guts of a ZX80.
  6. Unfortunately, we are a male heavy industry, we don’t want to be, we have a LOT of work to do to be better at inclusiveness and understanding barriers and pretty much everything necessary to address the balances…we know it, we are working on it, the rest of the world could also take some lessons JUST as we have learned from others.
  7. We typically like to disassemble things, not to cause problems but to understand how they work, to test them, to see if we can improve them and then to work out how to reassemble…often in a better way than they originally were….it’s on our blood and our brains, accept it please. I took the household vacuum cleaner apart when I was 8 to both see how it worked AND to make a hovercraft…these days I do the same thing with companies and their tech. 🙂
  8. Most of us are in this realm to do good, we don’t always go about it the right way, but the ultimate aim is to help things improve, to help humanity NOT go over the precipice or be sunk under the tsunami of technology that is upon us…we’re not perfect but we want to help…let us.
  9. Many of us are former military, government or something that involved using things other than keyboards…we are not the weak nerds that Hollywood likes to insinuate (neither are we the chiseled man-stud-muffin known as Chris Hemsworth) but again, when talking with us please understand that no only can we lob an exploit into your enterprise from across the globe we can probably also shoot out the escape key on your keyboard from 1,000 yards.
  10. Get out of the “English” mindset, again thanks to mainstream media the “hacker” is a white male in their 20’s and nothing could be further from the truth…the top country by scale is China, then followed by the US and then we have a HEAP of other countries most of whom don’t have the pale white skin associated with the typical “hacker”.
  11. Hacker and hacking is not a negative thing. The primary driving force for change and new inventions in this field is hacking, it is the simple ability to understand the status quo and be able to change it.

So, there’s a few, as a community we could probably write a books worth more, we have our issues and our challenges, we are growing up and working on HOW to be part of the enterprises we are charged with securing, how to be part of society even though many of us prefer to avoid it…and trying to work out how to navigate a path forward in this fragile technologically challenged world we exist in.

Hope that’s helped let the debates begin…

This appeared as a LinkedIn article, and is published with Chris Robert’s permission.

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Washington state Attorney General files lawsuit against Uber, demands $2,000 per violation

Uber

A week after Uber acknowledged a massive data breach, the Washington state Attorney General Bob Ferguson sued the taxi-aggregator for failing to report the incident. On November 28, 2017, Ferguson filed a multimillion-dollar lawsuit against Uber King County Superior Court, alleging that ride-sharing company violated the state’s revised data breach notification norm.

Ferguson has sought civil penalties of up to $2,000 per violation, which could result in millions of dollars if Uber loses. While asking Uber to cover the costs and fees associated with the lawsuit, Ferguson alleged that names and driver’s license numbers of at least 10,888 Uber drivers in Washington state were stolen without their being notified as state law requires.

A press release issued by the Attorney General’s Washington office said,  “the hackers obtained the names and driver’s license numbers of about 7 million drivers for the company. About 600,000 of those drivers live in the United States, and at least 10,888 live in Washington”.

Ferguson’s lawsuit is the first since the state’s consumer privacy laws were revised in 2015. According to the revised data breach law, “victims must be notified within 45 days of the breach’s discovery. If the breach affects more than 500 Washington residents, the attorney general’s office must also be notified.” In Uber’s case, the breach was notified to the attorney general after 372 days of occurrence.

During a press conference, Ferguson was quoted as saying, “instead of doing the right thing, following the law, and telling these thousands of Washingtonians they were at risk, Uber paid the hackers to delete the data and did not disclose the breach to anyone. That is stunning. It violates the spirit and the letter of the law. Our law is clear. When a data breach puts consumers at risk, businesses must inform them. That’s fair”.

Senior Counsel Shannon Smith and Assistant Attorneys General Tiffany Lee and Andrea Alegrett are handling the case.  Several states, including Missouri, Massachusetts and New York, have opened investigations, and the city of Chicago sued Uber on November 27, 2017, The News Tribune reported.

Last week, it was reported that Uber paid hackers $100,000 in ransom to destroy the stolen data to hide the breach that allegedly compromised personal information of about 57 million passengers around the world in October 2016. Shortly after the news broke, Uber fired its chief security officer Joe Sullivan and a deputy Craig Clark for concealing the hacking incident.

To investigate the breach, Uber CEO Dara Khosrowshahi said that his company hired Mandiant, a cybersecurity firm owned by FireEye and Matt Olsen, former general counsel of the U.S. National Security Agency, to restructure the company’s security teams and processes.

McAfee acquires Skyhigh Networks to provide cloud services

McAfee

On November 27, 2017, the independent cybersecurity firm McAfee acquired Skyhigh Networks for an undisclosed amount to bolster its new cloud business unit. In a statement, McAfee said the deal will usher in “a new era in cybersecurity”, as the two companies work to combine their cloud and endpoint security platforms.

Talking about the deal, Christopher D. Young, CEO of McAfee, said, “Skyhigh is an ideal complement to McAfee’s strategy—one focused on building and optimizing mission-critical cybersecurity environments for the future. McAfee and Skyhigh share more in common than values. We both aspire to make cybersecurity an accelerant to the limitless potential of our digital age. We both know that our employees are at the heart of everything we do. And, we both are committed to modernizing cybersecurity environments for the future”.

In a blog post titled “Skyhigh + McAfee = A New Era in Cybersecurity”, Skyhigh CEO Rajiv Gupta wrote, “with the expanded resources of McAfee, we will be able to tackle today’s security challenges on a much larger scale.”

“Skyhigh and McAfee’s goals are the same. We both want to create a world where enterprises can operate freely and securely to reach their full potential. As part of McAfee, we will have access to even greater resources to accelerate delivery of Skyhigh’s product roadmap, further advancing our vision of making cloud the most secure environment for business. And combined with McAfee’s endpoint security capabilities and operations center solutions with actionable threat intelligence, analytics and orchestration, we will be able to deliver a set of end-to-end security capabilities unique in the industry,” he further wrote.

As the result of the acquisition, Gupta will join McAfee as the new head of its cloud business unit. Last year, Skyhigh had raised over $106 million with investors including Sequoia, Greylock, and Salesforce, taking its total worth to $400 million. In 2011, Intel had bought McAfee but their deal got split early this year.

3 Chinese nationals indicted for hacking into Moody’s, Siemens, and Trimble

Three Chinese nationals have been charged by the U.S. prosecutors for hacking into Siemens AG, Trimble Inc, and Moody’s Analytics.  The trio tried to steal business secrets of three companies through “coordinated and unauthorized” cyber attacks between 2011 and 2017. The three accused have been identified as Wu Yingzhuo, Dong Hao, and Xia Lei.

An indictment that got unsealed on November 27, 2017, said all three of them were associated with Guangzhou Bo Yu Information Technology Company Ltd, a cybersecurity company located in Guangzhou in southern China. Two U.S. government officials told Reuters that Guangzhou Bo Yu is affiliated with China’s People’s Liberation Army Unit 61398.

During a hearing in federal court in Pittsburgh, Pennsylvania, on November 27, 2017, the acting U.S. attorney for Western Pennsylvania Soo C. Song said arrest warrants had been issued for the three men.   The indictment that was filed in September 2017 at a federal court in Pittsburgh, Pennsylvania, claims, “the hackers monitored email correspondence of an unidentified Moody’s economist; stole data from transportation, technology and energy units at Siemens; and targeted Trimble as it developed a new and more precise global navigation satellite system.”

Meanwhile, Chinese foreign ministry spokesman Geng Shuang told a press briefing that he was not aware of the details of the breaches, and said, “China firmly opposes and responds in accordance with the law to all forms of cyber attacks.”

Meanwhile, Trimble issued a statement saying, “Trimble responded to the incident and concluded that there is no meaningful impact on its business.” Moody’s spokesman told Reuters that the firm worked closely with investigators, and “to our knowledge, no confidential customer data or other personal employee information was compromised.” Siemens, on the other hand, did not comment.

 

Bug Bounty Programs: Closing Security Gaps

Bug, vulnerability, zero-day

This whitepaper is contributed by Tari Schreider, Chief Cybersecurity Strategist and Author, Prescriptive Risk Solutions, LLC

What is a Bug Bounty Program?

Bug or hacker bounty programs go by several names including vulnerability reward program, flaw disclosure, and hacker crowdsourcing. They all have one thing in common; they pay people for finding bugs in code. With few exceptions, programs pay cash for results. Once a bounty hunter submits proof of a vulnerability and the company sponsoring the program validates, cash is paid. Programs come in all sizes from small software companies who rely on voluntarily bug finding to large companies like Google and Facebook that pay out millions of dollars annually.

Today, several thousand companies offer a bounty program. HackerOne maintains what they claim is the most exhaustive list of known bug bounty programs.

How a program essentially works is you invite people to attempt to penetrate your network, web sites, etc. If they find a vulnerability, they document the flaw, you verify it and then issue a payment based on the conditions of your bounty. Easy peasy.

Bug Bounty Program Budgeting

Budgeting for a bounty program is a risk-based proposition. Ask yourself, what would it cost to fix a bug in production versus development or testing? Next, determine if that has ever happened, I am sure it has. Keep in mind that you only pay for successes in a bounty program. How much does it cost to keep a team of in-house security testers employed to find minimal bugs?

You can design a bounty program around any budget, even free, well almost – you still have to pay for using the platform. Bounty hunters want to make a name for themselves so some will work with programs that only provide kudos for finding bugs. This goes toward building their reputation and goal of becoming a much sought after super bug hunter.

Consider structuring your program around the priority rating of the bugs found. You may feel you want your bounty dollars to go only toward finding critical bugs and not those that pose an acceptable risk. Funding for the program can also be subsidized my marketing, as it is a way to promote your company as doing the right thing.

Penetration Testing vs. Bug Bounty Programs

Bounty programs have introduced an interesting argument, should I reduce my security testing staff and essentially outsource my security testing through a bug bounty program? In my experience, my clients that have compared results of in-house testing versus a bounty program has stated that bounty programs were far more successful in finding critical code flaws fast. The two main reasons are one, internal security testers do not think like hackers and two, the shear metric tons of hacker brainpower who are financially motivated to find bugs.

Penetration testing has become too bureaucratic with lawyers, contracts, rules of engagement, etc. I have seen many penetration testing projects take weeks or months to negotiate all while a bug bounty program at similar companies finding dozens of bugs in that same period of time. Now I am not advocating eliminating penetration testing from the mix, but rather that you consider it as an essential strategy to fast-path security testing of public facing critical code.

Unique Bug Bounty Programs

Bounties paid by companies can average from $200 to $200,000; however, an average reported by bugcrowd was $505.79. With a growing number of bounty hunters and bounty platforms, companies are looking for ways to gain notice by the industry’s top bug researchers.  United Airlines for example offers frequent flyer miles.

 

The following are several bounty programs that standout from the crowd:

Company Bounty
Apple $200,000 for highest category of bug – secure boot firmware bugs.
Google Donations to charities in conjunction with bounties.
Hack The Pentagon Pilot bug bounty program of $150,000 for hackers in return for the vulnerabilities they find in its public facing websites.
Kraken Payments made in bitcoins.
Netgear Submit a chain of bugs to receive a bonus.
PayPal Payments made to a PayPal account.
Uber Hacker loyalty reward program and bug treasure map.
United Airlines 50,000 to 1 Million award miles.

 

I suggest you work with your organization’s marketing department to come up with a unique and noticeable bounty payment to attract the best bug researchers. You certainly do not want to do what Yahoo did in 2013 and offer t-shirts to bug hunters for finding critical bugs in their code. This touched off such a hail of negative press against Yahoo the press referred to the incident as t-shirt gate. So a word to the wise, really think through what message your bounty program sends.

Bug Bounty & Disclosure Programs

A great way to model your bug bounty program is to view what other organizations have implemented. Thanks to bugcrowd and HackerOne, you can view nearly 2,000 with just a click of your mouse. Bugcrowd maintains an updated list on bounty and disclosure programs with direct links to respective program sites.

Think of this as security crowdsourcing of thousands of white hat hackers and professional security vulnerability researchers.

Bugcrowd can manage your program through a number of programs ranging from public (collective of thousands of hackers and researchers), private (invite only researchers) or on-demand (project-based invited researchers).

Bugcrowd provides a template for branding your bounty page, handles bounty payment, performs bug reporting triage and validation as well as provides comprehensive reporting on your program.

Bounty programs are effective and indispensable to your SDLC or DevOps operations. HackerOne and Detectify are two other bounty platforms you may wish to compare to bugcrowd. Bounty Factory is a European-based platform that focuses on EU rules and regulations related code flaws.

If you are just looking for a list of bug bounty programs, checkout bugsheet. This site offers a curated list of over 370 programs offering a collective 150 bounties.

Evolution of Bug Bounty Programs

Bounty programs have been around for many years. Jarrett Ridlinghafer while working at Netscape in 1995 established the first bounty program. He also coined the phrase “Bugs Bounty.”

Programs have progressed from casual in-house programs to sophisticated managed programs attracting only the highest profile bug hunters and everything in between. Bounty hunting has become an industry with providers ranging from hunters who just triage code with vulnerability scanners looking for low hanging fruit counting on the fact the sponsoring company never bothered to scan their own code to professional bug researchers.

Bounty hunting has also created a new breed of super hunter who devote their full-time energies to finding bugs as a profession.

What Type of Bugs are Found?

Bugcrowd reports the following types of critical bugs found by their researchers:

Bug bounty

Bug Bounty Program Tips

  1. Brand your program – marketing matters and bounty programs attract public attention.
  2. Make your program payout unique – you want to attract the most experienced bug hunters.
  3. Use a commercial bounty program management platform – do not reinvent the wheel.
  4. Clearly document the types of bugs you are willing to pay – ambiguous hunter instructions leads to wasted time and money.
  5. Scan your code before releasing it for bounty – you do not want to pay for bugs you should have caught.
  6. Structure a loyalty program to attract the best bug hunters – build a rapport with your star hunters.
  7. Integrate the bug bounty in DevOps – focus on finding bugs in development.
  8. Carefully document dupe flaws – the fastest way to tank your bounty program is to issue the kirk response “dupe” without proof.
  9. Expect poor submissions – over 90% of bounty programs will have little to no value, many researchers do not read the bounty guidelines.
  10. Expect your network probing – once the bounty is announced, researchers will start probing your network.

Conclusion

Bug bounty programs are a great strategy to include in your arsenal of secure coding and testing processes. They provide a vulnerability perspective that in-house programs typically cannot. These programs are ideal for due diligence and fast-pathing testing on highly visible and critical web sites. Invitation only bounties have approximately twice the success rate as public bounties due primarily to the quality of the bug researchers attracted, but they do cost more. Overall, this is something to consider in your mix of cybersecurity program practices.