上QQ阅读APP看书,第一时间看更新
Questions
- What are some differences between third-party marketplaces such as Bugcrowd and bug bounty programs offered by individual companies?
- Is it worth it to participate in programs that reward vulnerabilities with swag? Why or why not?
- What's a private bug bounty program?
- What are some resources you can use to find programs not covered in this chapter?
- What makes a site more or less attractive as a hunting ground for reward-eligible bugs?
- What is coordinated vulnerability disclosure?
- What steps can you take to minimize your legal liability during a pentesting session?