EPISODE · Mar 18, 2024 · 1H 11M
S1E03 - Bug Bounties
from The Boring AppSec Podcast · host The Boring AppSec Podcast
Welcome to the Boring AppSec Podcast! In Episode 3, we discuss all things bug bounties. The researcher side as well as the program owner's side. Enter at your own will as we have a lot of hot takes. References: We will try and add information about all the references we make here. Please enter rabbit holes at will :) Bug Bounty Platforms Bugcrowd - https://www.bugcrowd.com/ HackerOne - https://www.hackerone.com/ Intigrity - https://www.intigriti.com/ Synack - https://www.synack.com/ 2. Vulnerability Disclosure Process - https://www.cisa.gov/coordinated-vulnerability-disclosure-process 3. Google’s Project Zero vulnerability disclosure policy - https://googleprojectzero.blogspot.com/p/vulnerability-disclosure-faq.html 4. CVSS Calculator - https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator 5. Handling A Bug Bounty program From A Blue Team Perspective - https://www.youtube.com/watch?v=Vgy150R4bRw&t=0s 6. Consumer Bug Bounty Panel - https://www.youtube.com/watch?v=Y8X6pV7rdbA&t=0s Contacting Anshuman LinkedIn: https://www.linkedin.com/in/anshumanbhartiya/ Twitter: https://twitter.com/anshuman_bh Website: https://anshumanbhartiya.com/ Instagram: https://www.instagram.com/anshuman.bhartiya/ YouTube: https://www.youtube.com/@AnshumanBhartiya Contacting Sandesh LinkedIn: https://www.linkedin.com/in/anandsandesh/ Twitter: https://twitter.com/JubbaOnJeans/ Website: https://boringappsec.substack.com/
NOW PLAYING
S1E03 - Bug Bounties
No transcript for this episode yet
Similar Episodes
Mar 26, 2026 ·1m
Mar 19, 2026 ·34m
Feb 18, 2026 ·11m
Feb 11, 2026 ·45m