Bug Bounty

Mon
31
Aug

OwnCloud starts official Bug Bounty Program - Payments for valid Security Reports

OwnCloud starts official Bug Bounty Program - Payments for valid Security Reports

These week the vulnerability laboratory core research team started to participate in the official bug bounty program of the OwnCloud company. OwnCloud is a suite of client-server software for creating file hosting services and using them.

The developers of the Open-Source Cloud service OwnCloud have announced a Bug Bounty program. Researchers will be rewarded with up to 500 USD for accepted bugs. OwnCloud uses the another platform  for its Bounty program.

What is the maximum bounty?  We are offering rewards up to $500 for security vulnerabilities depending on the impact.

Which versions of ownCloud are in scope?  The scope for the Security Bug Bounty Program starts with ownCloud version 8.1.2.

Fri
28
Aug

PayPal Inc Bug Bounty 2015 - Stored Cross Site Vulnerability disclosed by Researcher

PayPal Inc Bug Bounty 2015 - Stored Cross Site Vulnerability disclosed by Researcher

Today one of the core team lab members discovered finally a paypal zero-day vulnerability to the public. The issue is about an application-side input validation vulnerability that allows to comprimise account credentials by manipulation of the secure payment procedure. The issue requires a low level of user interaction. The bug was finally rewarded by paypal with an amount of 750$.

Technical Details

Paypal SecurePayments domain is used by paypal users to do secure payments when purchasing from any shopping site, this secure payments page require Paypal users to fill some forms that include their Credit Card number, CVV2, Expiry date and more to finalize the payment and purchase the products via their Paypal account,

Pages

Subscribe to RSS - Bug Bounty