TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Hacking on Bug Bounties for Four Years

89 点作者 infosecau超过 4 年前

4 条评论

drsh0超过 4 年前
I've got to respect the transparency and spirit of this post. Major props. What I really love is seeing all the partnerships that have gone into some of his work over the years. Didn't realize how mammoth of a task some of these reports must have been that were only made possible via collaboration.
mellosouls超过 4 年前
Very informative and admirably transparent article.<p>From the other side (bounty program manager -this was linked to in another article on the assetnote blog):<p><a href="https:&#x2F;&#x2F;medium.com&#x2F;@collingreene&#x2F;bug-bounty-5-years-in-c95cda604365" rel="nofollow">https:&#x2F;&#x2F;medium.com&#x2F;@collingreene&#x2F;bug-bounty-5-years-in-c95cd...</a>
melvinroest超过 4 年前
A friend of mine looked at the feasibility of getting into bug bounty as a professional career. He mentioned that if you&#x27;re not specialized on a specific attack, you have no chance.<p>I think it&#x27;s quite refreshing to see that Shubham Shah is a strong counter example.
评论 #24514377 未加载
评论 #24524161 未加载
评论 #24514056 未加载
pakwa超过 4 年前
Hey Shubham, nice report and write up.<p>Do you see much demand on the mobile security side, either as a specialist or focussing on mobile bounties?