Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
No Result
View All Result
Home Uncategorized

Adobe launches bug bounty program that hands out high-fives, not cash

byCustoms Today Report
07/03/2015
in Uncategorized
Share on FacebookShare on Twitter

NEW YORK: Adobe has unveiled a bug bounty program that hands out high-fives, not cash. The web application vulnerability disclosure program announced and launched last month operates through HackerOne used by the likes of Twitter, Yahoo!, and CloudFlare, some of which provide cash or other rewards to those who disclose security messes.

Adobe’s program seeks out common flaws in its online services, including cross-site scripting; privileged cross-site request forgery; server-side code execution; authentication or authorisation flaws; injection vulnerabilities; directory traversal; information disclosure, and significant security misconfiguration.

You might also like

Pakistan to get $3b loan from Islamic Trade Financing Corporation

20/10/2024

Lahore I&I & Enforcement anti-smuggling operations achieve record success in early FY 2024-25

10/09/2024

“In recognition of the important role that independent security researchers play in keeping Adobe customers safe, Adobe launches a web application vulnerability disclosure program on the HackerOne platform,” wrote Adobe security program manager Pieters Ockers.

“Bug hunters who identify web application vulnerability in an Adobe online service or web property can now privately disclose the issue to Adobe while boosting their HackerOne reputation score.”

Hackers will need to be the first in for reporting a flaw and offer Adobe “reasonable” time to fix the flaws prior to public disclosure, Ockers says.

Smaller vulnerabilities such as the following are excluded:

  1. Logout and other instances of low-severity cross-site request forgery
  2. Perceived issues with password reset links
  3. Missing http security headers
  4. Missing cookie flags on non-sensitive cookies
  5. Clickjacking on static pages

The announcement comes as AirBnB launched its bug bounty on the popular HackerOne platform.

Bug bounties work best when they offer cash, according to BugCrowd engineer Drew Sing. In vulnerability program guidelines published July he says money is the best incentive to encourage researchers to conduct more regular and intense testing of products and services.

“A high priority security issue handled improperly could damage the reputation of the organisation … the development, IT and communications team are all critical components to a successful program,” Sing says.

The managed bug service recommends bounties should be published in an obvious location on websites, preferably located with the /security subdomain, and sport a dedicated security contact who is well-briefed in handling disclosures.

Tags: Adobe launches bug bounty program that hands out high-fivesnot cash

Related Stories

Pakistan to get $3b loan from Islamic Trade Financing Corporation

byCT Report
20/10/2024

ISLAMABAD: Islamic Trade Financing Corporation (ITFC) to provide Pakistan with a $3 billion loan, according to an official statement released...

Lahore I&I & Enforcement anti-smuggling operations achieve record success in early FY 2024-25

byCT Report
10/09/2024

LAHORE:  Regional Directorate of Customs Intelligence & Investigation has demonstrated exceptional performance in the first two months of the fiscal...

ICCI and CDA to join hands for tree plantation drive in Capital

byQaisar Mansoor
09/08/2023

ISLAMABAD: Islamabad Chamber of Commerce and Industry (ICCI) in collaboration with the Capital Development Authority (CDA) would jointly launch a...

Customs Officials Yawar Abbas & Tariq Mehmood kidnapped in Karachi

byCT Report
08/07/2023

KARACHI: Customs Intelligence Officer Yawar Abbas and Customs Preventive Officer Tariq Mehmood who were working against smuggling were kidnapped by...

Next Post

Indonesia seeks $7 billion foreign investment for port expansion

  • Terms and Conditions
  • Disclaimer

© 2011 Customs Today -World's first newspaper on customs. Customs Today.

No Result
View All Result
  • Transfers and Postings
  • Latest News
  • Karachi
  • Islamabad
  • Lahore
  • National
  • Chambers & Associations
  • Business
  • About Us

© 2011 Customs Today -World's first newspaper on customs. Customs Today.