Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security Management

1/11/2019
07:00 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now
50%
50%

Hyatt Hotels Kicks Off Bug Bounty Program

Hyatt Hotels is teaming with HackerOne on a new bug bounty hunting program that looks to pay up to $4,000 for 'critical' vulnerabilities in software.

Hyatt Hotels is looking to get into the bug bounty hunting game, with offers up to $4,000 to identify "critical" flaws in the software and applications that the company uses.

HackerOne, which has developed bug hunting platforms for client, will work with Hyatt to collect the vulnerabilities and pay out the rewards. Targets for this particular program include the main Hyatt website, hyatt.com, as well as m.hyatt.com, world.hyatt.com and the Hyatt mobile applications on both iOS and Android.

The program includes the $4,000 payout for critical vulnerabilities, as well as $1,200 for those deemed "high," $600 for "medium" and $300 for "low." The degree of the flaws is based on the Common Vulnerability Scoring Standard (CVSS).

The types of vulnerabilities and flaws that Hyatt and HackerOne are looking for, include: Novel origin IP address discovery, authentication bypass, back-end system access via front-end systems, business logic bypass resulting in financial gain to an attacker (e.g., forced rate change), container escape, discovery of Hyatt data on public cloud storage services, novel means of automating account checking or rate scraping (e.g., botting), publicly available cloud systems that may host Hyatt information, SQL injection, cross-site request forgery, exploitable cross-site scripting, and WAF bypass.

As this is ethical hacking, the bug bounty guidelines clearly state a list of "do nots" for those participating, including accessing customer data or credit card numbers, destroying data or posting data and sensitive information on public forums, such as GitHub.

This type of hacking operation in nearly the opposite of Zerodium, which pays a premium for undisclosed vulnerabilities that are then given to clients, including government agencies. (See Zerodium Ups Ante for Zero-Day Exploits, Especially in iOS.)

In a statement posted January 9, Hyatt executives claimed this is one of the first bug bounty programs implemented in the hospitality industry. It also comes as a time when rival hotel chain Marriott has come under scrutiny for a massive data breach affecting more than 300 million customer accounts, and included the theft of passport numbers and other personal data. (See Marriott Revises Data Breach Numbers as Investigation Continues .)

"At Hyatt, protecting guest and customer information is our top priority and launching this program represents an important step that furthers our goal of keeping our guests safe every day," Hyatt's CISO Benjamin Vaughn noted in a statement. "As one of the first global hospitality brands to launch this type of program, we extend the ways we care for our guests and deepen our commitment to protecting their sensitive information."

Hyatt manages more than 750 different hotels and other properties in 55 different countries.

In a question-and-answer interview posted with HackerOne, Vaughn noted that the bug bounty first started with a private, invitation-only event before going public. So far, $5,650 in payments have been issued and 14 different reports have been resolved.

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
'BootHole' Vulnerability Exposes Secure Boot Devices to Attack
Kelly Sheridan, Staff Editor, Dark Reading,  7/29/2020
Average Cost of a Data Breach: $3.86 Million
Jai Vijayan, Contributing Writer,  7/29/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-18112
PUBLISHED: 2020-08-05
Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are before version 4.8.3.
CVE-2020-15109
PUBLISHED: 2020-08-04
In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering address validations. This vulnerability allows a malicious customer to craft request data with parameters that allow changing the address of the current order without changing the shipm...
CVE-2020-16847
PUBLISHED: 2020-08-04
Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887.
CVE-2020-15135
PUBLISHED: 2020-08-04
save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced in version version 1.05 unintentionally breaks uploading so version v1.0.7 is the fixed version. This is patched by implementing Double submit. The CSRF...
CVE-2020-13522
PUBLISHED: 2020-08-04
An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can allow an unprivileged user to delete any file on the filesystem. An attacker can send a malicious IRP to trigger this vulnerability.