Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security Management

1/11/2019
07:00 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now
50%
50%

Hyatt Hotels Kicks Off Bug Bounty Program

Hyatt Hotels is teaming with HackerOne on a new bug bounty hunting program that looks to pay up to $4,000 for 'critical' vulnerabilities in software.

Hyatt Hotels is looking to get into the bug bounty hunting game, with offers up to $4,000 to identify "critical" flaws in the software and applications that the company uses.

HackerOne, which has developed bug hunting platforms for client, will work with Hyatt to collect the vulnerabilities and pay out the rewards. Targets for this particular program include the main Hyatt website, hyatt.com, as well as m.hyatt.com, world.hyatt.com and the Hyatt mobile applications on both iOS and Android.

The program includes the $4,000 payout for critical vulnerabilities, as well as $1,200 for those deemed "high," $600 for "medium" and $300 for "low." The degree of the flaws is based on the Common Vulnerability Scoring Standard (CVSS).

The types of vulnerabilities and flaws that Hyatt and HackerOne are looking for, include: Novel origin IP address discovery, authentication bypass, back-end system access via front-end systems, business logic bypass resulting in financial gain to an attacker (e.g., forced rate change), container escape, discovery of Hyatt data on public cloud storage services, novel means of automating account checking or rate scraping (e.g., botting), publicly available cloud systems that may host Hyatt information, SQL injection, cross-site request forgery, exploitable cross-site scripting, and WAF bypass.

As this is ethical hacking, the bug bounty guidelines clearly state a list of "do nots" for those participating, including accessing customer data or credit card numbers, destroying data or posting data and sensitive information on public forums, such as GitHub.

This type of hacking operation in nearly the opposite of Zerodium, which pays a premium for undisclosed vulnerabilities that are then given to clients, including government agencies. (See Zerodium Ups Ante for Zero-Day Exploits, Especially in iOS.)

In a statement posted January 9, Hyatt executives claimed this is one of the first bug bounty programs implemented in the hospitality industry. It also comes as a time when rival hotel chain Marriott has come under scrutiny for a massive data breach affecting more than 300 million customer accounts, and included the theft of passport numbers and other personal data. (See Marriott Revises Data Breach Numbers as Investigation Continues .)

"At Hyatt, protecting guest and customer information is our top priority and launching this program represents an important step that furthers our goal of keeping our guests safe every day," Hyatt's CISO Benjamin Vaughn noted in a statement. "As one of the first global hospitality brands to launch this type of program, we extend the ways we care for our guests and deepen our commitment to protecting their sensitive information."

Hyatt manages more than 750 different hotels and other properties in 55 different countries.

In a question-and-answer interview posted with HackerOne, Vaughn noted that the bug bounty first started with a private, invitation-only event before going public. So far, $5,650 in payments have been issued and 14 different reports have been resolved.

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/9/2020
Considerations for Seamless CCPA Compliance
Anurag Kahol, CTO, Bitglass,  7/2/2020
Introducing 'Secure Access Service Edge'
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  7/3/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-12421
PUBLISHED: 2020-07-09
When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability affects Firefox ESR < 6...
CVE-2020-12422
PUBLISHED: 2020-07-09
In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds write, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.
CVE-2020-12423
PUBLISHED: 2020-07-09
When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox may have loaded the DLL, leading to arbitrary code execution. *Note: This issue only affects the Windows operating system; other operating sys...
CVE-2020-12425
PUBLISHED: 2020-07-09
Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information disclosure. This vulnerability affects Firefox < 78.
CVE-2020-12426
PUBLISHED: 2020-07-09
Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 78.