Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

7/12/2016
09:00 AM
Sean Martin
Sean Martin
Slideshows
Connect Directly
LinkedIn
RSS
E-Mail
50%
50%

Profiles Of The Top 7 Bug Hunters From Around the Globe

'Super hunters' share a common goal: to find the most high impact valid bugs before a bad guy does.
Previous
1 of 8
Next

Image Source: imsmartin/Bugcrowd

Image Source: imsmartin/Bugcrowd

The true value of crowdsourced security lies in the diversity of knowledge, experience, and bug-hunting methods employed by security researchers. Additional value is oftentimes further defined by differing cultures, perspectives and backgrounds depending on geographic location. Bugcrowd’s crowdsourced bug-bounty program, for example, is quite diverse, with participating researchers from no fewer than 112 countries organized into several regions.

While there may be a lot of differences between each of the 112 countries, the top researchers – many of them described as ‘Super Hunters’ — from each region appear to share a common goal: to find the most, high impact valid bugs before a bad guy does.

To underscore the value these individuals bring to the cybersecurity table, this slide show will provide seven profiles for the top-ranked Bugcrowd researchers, selecting one from each of the top-submitting regions, chosen by the largest volume of bug submissions.

To help understand the data presented with each researcher, refer to the following definitions:

  • Acceptance Rate: Best explained as a comparison of valid to invalid reports.
  • Average Priority: When taken in context with a researcher’s rank and Acceptance Rate, this can help recognize outstanding researchers who consistently submit high impact vulnerabilities, but may be lower volume in their submissions.
  • Kudos Points: These are intended to recognize researchers for their valid vulnerability reports, independent of monetary or swag prizes associated with the bounty program. The more severe the vulnerability impact, the greater the points awarded (from 5 to 20).

This presentation is a precursor to a new report being developed by Bugcrowd which will take a look at the psychology of bug hunters, what motivates them, and why the researchers look very different from one another.

Before we begin, imsmartin would like to thank the Bugcrowd team for making this information available to our team.

 

Sean Martin is an information security veteran of nearly 25 years and a four-term CISSP with articles published globally covering security management, cloud computing, enterprise mobility, governance, risk, and compliance—with a focus on specialized industries such as ... View Full Bio

Previous
1 of 8
Next
Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Where Businesses Waste Endpoint Security Budgets
Kelly Sheridan, Staff Editor, Dark Reading,  7/15/2019
US Mayors Commit to Just Saying No to Ransomware
Robert Lemos, Contributing Writer,  7/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-12815
PUBLISHED: 2019-07-19
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.
CVE-2019-13569
PUBLISHED: 2019-07-19
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
CVE-2019-9228
PUBLISHED: 2019-07-19
** DISPUTED ** An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management TELNET features allow remote attackers to cause a denial of service (connection slot e...
CVE-2019-12725
PUBLISHED: 2019-07-19
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.
CVE-2019-11989
PUBLISHED: 2019-07-19
A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to cause a denial of service. The versions and platforms of Agent Option modules that are impacted are as follows: 10.0 for Apache 2.2 on RHEL 5 and 6, 10.0 for Apache 2.4 on RHEL 7, ...