[ / / / / / / / / / / / / / ] [ dir / baphomet / caco / choroy / christ / dbv / dempart / gfl / leandro ][Options][ watchlist ]

/tech/ - Technology

You can now write text to your AI-generated image at https://aiproto.com It is currently free to use for Proto members.
Email
Comment *
Verification *
File
Select/drop/paste files here
Password (Randomized for file and post deletion; you may also set your own.)
* = required field[▶ Show post options & limits]
Confused? See the FAQ.
Expand all images

File (hide): 634e31e70df0f01⋯.png (501.18 KB, 919x391, 919:391, afafafe.png) (h) (u)

[–]

 No.1042593>>1042682 >>1042736 >>1042797 >>1042801 >>1043306 >>1043592 >>1043778 [Watch Thread][Show All Posts]

Are bug bounty programs a meme? Can you actually make money of this shit? Any experiences?

https://hackerone.com/reports/429679

What do you think how hard it is to get to that level? I've built some foundation, studying on Cybrary Network+, Comptia A+, Security+, Linux+ and currently reading TCP/IP illustrated. I need to study Web app stuff right?

 No.1042605>>1043592

if you're a good hacker you're making actual hacks for money. These "hackers" earn next to nothing with the cheap bounties companies offer.


 No.1042609>>1042732 >>1044526

if your a good hacker you would fix the double post bug here as your first bounty


 No.1042651>>1042687

Bug bounties are a complete meme. Most of the bounties go to the same handful of people who already do this professionally in some other way; you are basically competing with a bunch of teenagers for peanuts.


 No.1042682

File (hide): f1b412439d35706⋯.jpg (1.08 MB, 2082x1171, 2082:1171, hands-diversity.jpg) (h) (u)

>>1042593 (OP)

We call them bug chasers now


 No.1042687>>1042721

>>1042651

This. Even if you had zero-days the spooks pay MUCH better.


 No.1042714>>1043592

Any "hacker" earning their money doing bug bounties is a skid that knows few tricks here and there and never amounts to anything.

They think it is a valuable experience that might land them a job but they're deluding themselves into literal shit digging work.


 No.1042721

>>1042687

But what if you were doing them not for the money, but to piss the spooks off by fixing zerodays in software they like to hack?


 No.1042732>>1042753

>>1042609

I just want to know how I've only ever seen this problem on /tech/. CSS problem or what?


 No.1042736

>>1042593 (OP)

>I need to study Web app stuff right?

Not really. Learn how to actually work on malware, reverse engineer it, and detect it (a/v and traffic signatures). You'll make way more money doing it and you won't just be a skid.


 No.1042753

>>1042732

It comes from faggots who don't see their post show up, so they post it again. Then the original post shows up, and then the second post.

>I've only ever seen this problem on /tech/

I've seen it on reddit too. Think there was a bug one time, because I saw a thread where everyone's post had doubled. It's more egregious on /tech/ because no one can delete threads except the BO.


 No.1042797>>1043306

>>1042593 (OP)

>find a lethal bug

>use bug and earn as much as you can

>anomalous attacks

>find another lethal bug

>sell old bug

>repeat.


 No.1042801

>>1042593 (OP)

They're memes. If you contribute to an open source project anyway, you can earn beer money doing random companie's specific feature requests, but it's not a way to support yourself.


 No.1043306>>1043592

>>1042593 (OP)

Yes they are a meme. It's 100% marketing. "Look bruh discord has a bug bounty, it must be better than conject0r, even though it crashes every 5 seconds". Bug bounties don't and never have made software any more secure. The software industry is a joke and as an obvious collary, so is the security of all software.

>Any experiences?

Oh you're one of those people.

>>1042797

>do attack A that nobody else has done

>sell it to company a year later after they figured it out

genius. is there a way to collect bug bounties anonymously?


 No.1043329>>1043333 >>1043339 >>1043592

File (hide): 0dab794b0859fb4⋯.png (184.48 KB, 838x683, 838:683, 14298529849.png) (h) (u)

>its a meme

>meanwhile a 19 year old self taught guy from some 3rd world shithole gets paid 1million

https://www.infosecurity-magazine.com/news/19-year-old-awarded-more-than-1m-1-1/

/tech/ forever BTFO


 No.1043333>>1043334 >>1043592

>>1043329

from a software engineering standpoint it's a meme, but that's something you wont understand. also whatever news article you link to may or may not just be marketing/hype


 No.1043334

>>1043333

seething


 No.1043339>>1043341 >>1043342

>>1043329

sounds very meme to me. why is it always some kid that does these instead of people that call themselves "professionals" and do that shit as their job


 No.1043341

>>1043339

i dunno about the "whitehat community" but everyone i know who's actually good at hacking became millionares 10 years ago and wouldn't waste their time with this shit. point is, software industry is shit


 No.1043342>>1044344

>>1043339

to get young retards into the field to flood the market suppress wage costs


 No.1043592>>1044182

>>1042593 (OP)

Hackerone and bugcrowd are decent. I know some people pull bounties from those programs on the regular.

Things you will need to know for real hacking. Look this shit up on YouTube.

Assembly programming

Shellcode

Egghunting

Exploit development

That or learn relational database applications development then Learn SQL injection and things like that for Web applications penetration testing.

>>1042605

True blackhats can make more money in given circumstance. That and something like 95% of moralfags are leftists. Fuck the security industry. But if a guy wants to make some cash on bug bounties whatever. I'm over it.

>>1042714

This is absolutely true. Doing tech work on prospect is not recommended. Most people will make up some reason they are not going to pay you.

>>1043306

This is categorically false. Finding and fixing bugs makes software more secure. Hackers finding security holes and responsibly reporting them to developer helps developers tremendously.

>>1043329

True, there are some success stories.

>>1043333

Also true. Nearly everything in the security industry is a scam. Best bet just write hack tools and put them on Github to build a portfolio in hopes of getting offered a real job. That or just hack because you love it.


 No.1043778

>>1042593 (OP)

You would be better off and make more by catching actual bugs OP. Media has a successor bias reporting the only 2 or 3 over successful cases when the average success is very low and an average bug catcher actually makes the double of an average bug bounty hunter. Don't treat it as anything more than a part time job.


 No.1044182

>>1043592

>>>1043306

This is categorically false. Finding and fixing bugs makes software more secure.

No it fucking doesn't, and since you list "Egghunting" as if it's some fundamental wisdom you come off as yet another skidd0. Fixing one vuln someone finds makes the software slighty better at best, does fuck all to change the attitude of the "software engineers", and gets you and the vendor some PR.

>Hackers finding security holes and responsibly reporting them to developer helps developers tremendously.

No it doesn't. It's literally just a market.


 No.1044344

>>1043342

THIS. IT'S ALWAYS ABOUT THIS!


 No.1044526


 No.1052565

HAPAS ARE SUPERIOR TO WHITES


 No.1056296

I smell rats.


 No.1056394

These are our enemies. Why are we supporting them?


 No.1056592

Whatcha sliding Chaim?


 No.1056852

Whatcha sliding MOSHE?


 No.1057286

Yeah, right, and the moon is made of cheese.




[Return][Go to top][Catalog][Screencap][Nerve Center][Cancer][Update] ( Scroll to new posts) ( Auto) 5
30 replies | 2 images | Page ?
[Post a Reply]
[ / / / / / / / / / / / / / ] [ dir / baphomet / caco / choroy / christ / dbv / dempart / gfl / leandro ][ watchlist ]