Not All Bug Bounty Programs Are the Same: Finding Your Target

Not All Bug Bounty Programs Are the Same: Finding Your Target

Finding the right bug bounty program to target is the crucial first step to becoming a successful bug bounty hunter. With the rapid emergence of many programs over the past few years, it’s challenging to figure out which ones will provide the best monetary rewards, experience, and learning opportunities.

A bug bounty program is an initiative in which a company invites ethical hackers to attack its products and service offerings to find security vulnerabilities. But how should you pick a program? And how should you prioritize their different metrics, such as the asset types involved, whether the program is hosted on a platform, whether it’s public or private, the program’s scope, the payout amounts, and response times


The State of the Industry

Bug bounties are currently one of the most popular ways for organizations to receive feedback about security flaws. Large corporations, like PayPal and Facebook, as well as government agencies like the US Department of Defense, have all embraced the idea. Yet, not too long ago, reporting a vulnerability to a company would have more likely landed a person in legal trouble than gotten them a reward.

In 1995, Netscape launched the first-ever bug bounty program. The company encouraged users to report bugs found in its brand-new browser, the Netscape Navigator 2.0, introducing the idea of crowdsourced security testing to the internet world. Mozilla launched the next corporate bug bounty program nine years later, in 2004, inviting users to identify bugs in the Firefox browser.

But it was not until the 2010s that offering bug bounties became a popular practice. That year, Google launched its program, and Facebook followed suit in 2011. These two programs truly kick-started the trend of using bug bounties to augment a corporation’s in-house security infrastructure.

The Rise of Bug Bounty Platforms

As bug bounties became a more well-known strategy, bug-bounty-as-a-service platforms emerged. These platforms help companies set up and operate their programs. For example, they provide a place for companies to host their programs, a way to process reward payments, and a centralized place to communicate with bug bounty hunters.

The two largest of these platforms, HackerOne and Bugcrowd, both launched in 2012. Following them, a few more platforms, such as Synack, Cobalt, and Intigriti, came to the market. These platforms and managed bug bounty services allow even companies with limited resources to run a security program. Today, large corporations, small startups, nonprofits, and government agencies alike have adopted bug bounties as an additional security measure and a fundamental piece of their security policies.

The term security program usually refers to information security policies, procedures, guidelines, and standards in the larger information security industry. In the context of bug bounties, the term program or bug bounty program refers specifically to a company’s bug bounty operations.

Today, tons of programs exist, all with their unique characteristics, benefits, and drawbacks. Let’s examine these factors to help you make an informed choice.


Asset Types: Choosing Your Attack Surface

In the context of a bug bounty program, an asset is an application, website, or product that a hacker can target. There are different types of assets, each with its own characteristics, requirements, and pros and cons. After considering these differences, you should choose a program with assets that play to your strengths, based on your skill set, experience level, and preferences.

Social Sites and Applications

Anything labeled social has a lot of potential for vulnerabilities because these applications tend to be complex and involve a lot of interaction among users, and between the user and the server. This first type of bug bounty program targets social websites and applications.

The term social application refers to any site that allows users to interact with each other. Many programs belong to this category: examples include the bug bounty program for HackerOne and programs for Facebook, Twitter, GitHub, and LINE.

General Web Applications

General web applications are also a good target for beginners. This category refers to any web applications that do not involve user-to-user interaction. Instead, users interact with the server to access the application’s features. Targets that fall into these categories can include static websites, cloud applications, consumer services like banking sites, and web portals of Internet of Things (IoT) devices or other connected hardware. Like social sites, they are also quite diverse and lend themselves well to a variety of skill levels. Examples include the programs for Google, the US Department of Defense, and Credit Karma.

Mobile Applications (Android, iOS, and Windows)

After you get the hang of hacking web applications, you may choose to specialize in mobile applications. Mobile programs are becoming prevalent, as most web apps have a mobile equivalent nowadays. They include programs for Facebook Messenger, the Twitter app, the LINE mobile app, the Yelp app, and the Gmail app.

APIs

Application Programming Interfaces (APIs) are specifications that define how other applications can interact with an organization’s assets, such as to retrieve or alter their data. For example, another application might be able to retrieve an application’s data via HyperText Transfer Protocol (HTTP) messages to a certain endpoint, and the application will return data in the format of Extensible Markup Language (XML) or JavaScript Object Notation (JSON) messages.

Source Code and Executables

If you have more advanced programming and reversing skills, you can give source code and executable programs a try. These programs encourage hackers to find vulnerabilities in an organization’s software by directly providing hackers with an open source codebase or the binary executable. Examples include the Internet Bug Bounty, the program for the PHP language, and the WordPress program.

Hardware and IoT

Last but not least are hardware and IoT (Internet of Things) programs. These programs ask you to hack devices like cars, smart televisions, and thermostats. Examples include the bug bounty programs of Tesla and Ford Motor Company.


Bug Bounty Platforms vs. Independently Hosted Programs

Companies can host bug bounty programs in two ways: through bug bounty platforms and on independently hosted websites.

As a bug bounty hunter, should you hack on a bug bounty platform, or should you go for companies’ independently hosted programs?

The Pros of Platforms

The Cons of Platforms


Other Key Metrics: Scope, Payouts, and Response Times

What other metrics should you consider when picking a program, besides its asset types and platform? On each bug bounty program’s page, metrics are often listed to help you assess the program. These metrics give insight into how easily you might be able to find bugs, how much you might get paid, and how well the program operates.

Program Scope

First, consider the scope. A program’s scope, specified on its policy pages, defines what and how you are allowed to hack. There are two types of scopes:

  1. Asset Scope: Tells you which subdomains, products, and applications you can hack.
  2. Vulnerability Scope: Specifies which vulnerabilities the company will accept as valid bugs.

Crucial Rule: Assets that are listed as in scope are the ones you are allowed to hack. Assets that are listed as out-of-scope are off-limits to bug bounty hunters. Be extra careful and abide by the rules! Hacking an out-of-scope asset is illegal.

Typical out-of-scope vulnerabilities include: Self-XSS, Clickjacking, Missing HTTP headers and other best practices without direct security impact, Denial-of-Service attacks, and Use of known-vulnerable libraries/automated scanner results without proof of exploitability.

Payout Amounts

The next metric you should consider is the program’s payout amounts. There are two types of payment programs:

  1. Vulnerability Disclosure Programs (VDPs): These are reputation-only programs, meaning they do not pay monetary rewards for findings but often offer rewards such as reputation points and swag.
    • VDP Benefits: They are a great way to learn about hacking if making money is not your primary objective. Since they don’t pay, they’re less competitive, and so easier to find bugs in. You can use them to practice finding common vulnerabilities and communicating with security engineers.
  2. Bug Bounty Programs: These offer varying amounts of monetary rewards for your findings. In general, the more severe the vulnerability, the more the report will pay.

Response Time

Finally, consider the program’s average response time. Some companies will handle and resolve your reports within a few days, while others take weeks or even months to finalize their fixes. Delays often happen because of the security team’s internal constraints (lack of personnel, delay in issuing security patches, lack of funds) or because researchers have sent bad reports without clear reproduction steps.


Public vs. Private Programs

Most bug bounty platforms distinguish between public and private programs.

The Advantage of Private Programs

Participating in private programs can be extremely advantageous.

How to Get Invited to Private Programs

Companies send private invites to hackers who have proven their abilities. Getting invites to private programs isn’t difficult once you’ve found a couple of bugs. Different bug bounty platforms will have different algorithms to determine who gets the invites, but here are some tips:

  1. Submit Valid Bugs to Public Programs: To get private invites, you often need to gain a certain number of reputation points on a platform, and the only way to begin earning these is to submit valid bugs to public programs.
  2. Focus on High-Impact Vulnerabilities: These vulnerabilities will often reward you with higher reputation points and help you get private invites faster.
  3. Complete Platform Challenges: On some bug bounty platforms, like HackerOne, you can also get private invites by completing tutorials or solving Capture the Flag (CTF) challenges.
  4. Do Not Spam: Submitting nonissues often causes a decrease in reputation points. Most bug bounty platforms limit private invites to hackers with points above a certain threshold.
  5. Be Polite and Courteous: Be polite and courteous when communicating with security teams. Being rude or abusive will probably get you banned from the program and prevent you from getting private invites from other companies.

Choosing the Right Program for Success

Bug bounties are a great way to gain experience in cybersecurity and earn extra bucks. But the industry has been getting more competitive. As more people are discovering these programs and getting involved in hacking on them, it’s becoming increasingly difficult for beginners to get started. That’s why it’s important to pick a program that you can succeed in from the very start.

Before developing a bug hunter’s intuition, you often have to rely on low-hanging fruit and well-known techniques. This means many other hackers will be able to find the same bugs, often much faster than you can. It’s therefore a good idea to pick a program that more experienced bug hunters pass over to avoid competition. You can find these underpopulated programs in two ways:

  1. Look for Unpaid Programs (VDPs): Try going for Vulnerability Disclosure Programs (VDPs) first. Unpaid programs are often ignored by experienced bug hunters, since they don’t pay monetary rewards. But they still earn you points and recognition, which might be just what you need to get an invite to a private, paid program.
  2. Go for Programs with Big Scopes: Picking a program with a large scope means you’ll be able to look at a larger number of target applications and web pages. This dilutes the competition, as fewer hackers will report on any single asset or vulnerability type.

Remember to go for programs with fast response times to prevent frustration and get feedback as soon as possible.

One last thing that can be incorporated into your decision process is the reputation of the program. If you can, gather information about a company’s process through its disclosed reports and learn from other hackers’ experiences. Does the company treat its reporters well? Are they respectful and supportive? Do they help you learn? Pick programs that will be supportive while you are still learning, and programs that will reward you for the value that you provide.

Choosing the right program for your skill set is crucial if you want to break into the world of bug bounties. This guide should have helped you sort out the various programs that you might be interested in. Happy hacking!


A Quick Comparison of Popular Programs

After you’ve identified a few programs that you are interested in, you could list the properties of each one to compare them. Below, let’s compare a few of the popular programs.

ProgramAsset TypeIn-Scope Assets (Examples)Payout Amount (Min/Range)Response Time Metrics (Average)
HackerOneSocial sitehackerone.com, api.hackerone.com, *.vpn.hackerone.net, etc.$500–$15,000+Fast. Response: 5 hours. Triage: 15 hours.
FacebookSocial site, non-social site, mobile site, IoT, and source codeInstagram, Internet.org / Free Basics, Oculus, Workplace, WhatsApp, Portal, etc.$500 minimumBased on experience, quite fast.
GitHubSocial siteblog.github.com, community.github.com, resources.github.com, etc.Not explicitly listed, but generally competitiveMetrics not provided in the original text.

Exit mobile version