Vulnerabilities / Threats
6/13/2013
05:27 PM
Mike Rothman
Mike Rothman
Commentary
50%
50%

0-Day The (Bug) Bounty Hunter

Companies increasingly offer bug bounties to help find vulnerabilities and threats. This is an opportunity for those looking to get into security

Whenever I go to a conference, inevitably I'll meet a college student or a younger kid interested in security. They want to know how I got to -- well, wherever I am -- and how they can sit in coffee shops all day. Once I get over the shock that I had already graduated from college before these kids were born, they usually want some guidance on how to get started in the business.

For quite a while, I told them to volunteer their time configuring networks and protecting data for organizations that didn't have internal resources to do so. You know, religious organizations, charities, youth groups, whatever. Just get some experience and use that to parlay into a corporate internship -- and eventually a job. I also told them about the need to learn some coding kung fu, since application security was going to be a big problem for many years to come. Even a blind squirrel finds the nut every so often.

As opposed to taking Java courses (which seemed like a good idea at the time), there's now another alternative. These kids can become bug bounty hunters. Don't turn up your nose yet. Hear me out a bit. Kids with an interest in security today have all sorts of ways to learn about security, but a bunch can land them in hot water. They can play around with DDoS tools, social-engineer their way into the big evil company, or break into their high school's network with Metasploit. And many do exactly that. Not because they are bad kids, but because they like to hack things, and the tools are out there and easy to use.

Consider a more productive approach. With Google recently increasing the bounty to find bugs and other companies taking a similar approach, those meddling kids can turn their talents to finding defects in these software products. Not only can the kids make a shekel or two, but they'll end up with invaluable experience and a few notches in their belts when they find bugs. And they will find stuff -- it's software, after all. This practical experience looks good to recruiters and other folks looking to find talented candidates for the tons of open security jobs.

To be clear, finding bugs is more about offense than defense. But it's a start, and once someone can successfully break things, they'll have a good perspective on how to protect it. If that's the direction they want to go in. With the security skills shortage in the industry, there will be plenty of opportunities for those who want to stay on an offensive track. And I don't mean those less-than-hygienic folks we all know and love.

It turns out these bug bounty programs are the rare win-win for both parties. The companies get very cheap Q/A help. Even if they pay $10K for a juicy bug, the typical qualified tester costs 12 to 15 times that (fully loaded) per year. That person would need to find a lot of juicy bugs to justify hiring them full time. Even better, the company gets exclusive access to the defect, presumably to fix it before the threat becomes a weaponized exploit.

Now, of course, if the enterprising prodigy realizes governments will pay really big money for unique bugs, they can skip a few steps in their career progression. But the NSA already knows about those bugs, right?

Mike Rothman is President of Securosis and author of The Pragmatic CSO. Check him out on the Twitterz at @securityincite.

Mike's bold perspectives and irreverent style are invaluable as companies determine effective strategies to grapple with the dynamic security threatscape. Mike specializes in the sexy aspects of security, like protecting networks and endpoints, security management, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2037
Published: 2014-11-26
Openswan 2.6.40 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads. NOTE: this vulnerability exists because of an incomplete fix for CVE 2013-6466.

CVE-2014-6609
Published: 2014-11-26
The res_pjsip_pubsub module in Asterisk Open Source 12.x before 12.5.1 allows remote authenticated users to cause a denial of service (crash) via crafted headers in a SIP SUBSCRIBE request for an event package.

CVE-2014-6610
Published: 2014-11-26
Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated users to cause a denial of service (crash) via an out of call message, which is not properly handled in the ReceiveFax dia...

CVE-2014-7141
Published: 2014-11-26
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.

CVE-2014-7142
Published: 2014-11-26
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?