Posts

Showing posts with the label Bug Bounty program

User Account Timeline Manipulation overlooked by Facebook!

Image
A Polish security researcher & analyst with the Twitter username ‘Lasq’ revealed that the Social Media Giant, Facebook is afflicted by  Clickjacking Bug , which automatically add  spam links  on the Facebook user’s wall. The security professional discovered a technique used by miscreant & used Bug bounty program to submit the report to the company. According to the resources, the ongoing Spam Campaign on Facebook seems to have a prolonged life as Facebook has denied dismissing Clickjacking Bug because it does not alters the state of the account. Behavior of Clickjacking Bug The Polish security expert began to analyze the Spam Campaign on Facebook after he observed many of his friends broadcasted a link to a website with amusing pictures. The Facebook users had to confirm that they were at least 16 years old before they could access humorous content. Once the user clicks on the button, he will be  redirected to a page  with amusing &  c...

HP Printer announces a whopping $10,000 Bug Bounty to Improve Network Security

Image
Vulnerability researchers, here comes a must not be missed opportunity for you! HP Inc. has rolled a bug bounty program to felicitate researchers with a whopping sum between $500 and $10,000 for finding security flaws in a range of HP printers. Bugs found in the vendor’s Enterprise LaserJet machines and multi-function printer (MFPs), such as the A3 and A4 will also be acknowledged. The amount of the reward is based on the severity of the discovered vulnerabilities! Keeping in mind the fact that printers are the weakest link in an organization and the vulnerabilities in these can be exploited to infect the entire chain in the network in various malicious campaigns; HP launches Bug Bounty program and announces its team venture with Bugcrowd on July 31st 2018. Bugcrowd is a bug bounty platform that manages vulnerability disclosure programs and  uses crowdsourced model to find vulnerabilities. In this private program, researchers will be sent the invite to join the program. The...