Skip to main content

Facebook to start paying Bug finders




Facebook has decided it’s a good idea to offer up a $500 bounty for exploits reported to the Facebook security team. They are claiming they will pay out larger amounts for ‘truly significant’ bugs, but they aren’t qualifying that claim with any guidelines or amounts.

Facebook is going to pay hackers to find problems with its website — just so long as they report them to Facebook’s security team first.

The company is following Google and Mozilla in launching a Web “Bug Bounty” program. For security related bugs — cross site scripting flaws, for example — the company will pay a base rate of $500. If they’re truly significant flaws Facebook will pay more, though company executives won’t say how much.

“In the past we’ve focused on name recognition by putting their name up on our page, sending schwag out and using this an avenue for interviews and the recruiting process,” said Alex Rice, Facebook’s product security lead. “We’re extending that now to start paying out monetary rewards.”

On Friday, Facebook will launch a new Whitehat hacking portal where researchers can sign up for the program and report bugs.

Many hackers go public with the software and website flaws they find to gain prestige. Finding an important bug on a widely used website such as Facebook can help make a journeyman hacker’s career, and going to the press with the issue can make him — or her — famous.
But talking about the issue before Facebook has had a chance to patch it, can be risky for Facebook users. In recent years, other companies have started these bug bounty programs to encourage hackers to keep quiet about the problems they find until they are patched.


Google pays between $500 and $3,133.70, depending on the severity of the flaw.

Google started to pay for browser bugs in early 2010, and then in November it expanded the program to cover bugs in its Web properties too.
The Web bug bounty program has helped Google uncover a lot of programming errors in the past eight months, most of which have been in Google’s lesser-known products, a company spokesman said this week.

Google sees its Web program as a big success. “We’re very happy with the success of our vulnerability reward program so far. We’ve already given out $300,000 and have seen a variety of interesting bugs,” the spokesman said in an e-mail message.

Facebook’s security team already engages in a lot of dialogue between security researchers and its own programmers. The company is contacted between 30 and 50 times each week by hackers. Their information leads to an average of about one to three “actionable bugs,” per week, Rice said. Most of these are cross-site scripting or cross-site request forgery issues. These are both very common Web programming errors that could be abused by scammers and cybercrooks to rip off Facebook users.

Comments

Popular posts from this blog

Sony India launches new camera RX10 M4

Sony’s New RX10 IV Combines World’s Fastest1 AF and 24 fps Continuous Shooting with Versatile 24-600mm F2.4-F4 Zoom Lens ·           World’s fastest 1  0.03 sec high speed AF with 315 focal-plane phase-detection AF points ·           High-speed 24fps shooting with AF/AE tracking ·           ZEISS® Vario-Sonnar T* 24-600mm F2.4-F4 Large Aperture, High Magnification Zoom Lens ·           Touch Focus ·           4K Movie Recording with full pixel readout without pixel binning New Delhi, 10 th  October, 2017 –  Sony, a worldwide leader in digital imaging and the world’s largest image sensor manufacturer today announced an addition to its acclaimed Cyber-shot® RX10 series, the  RX10 IV  (model DSC-RX10M4). Building o...

Gionee Elife S Plus: Redefining smartphones

After a great successful launch of Elife series of smartphones. The company has come up with Gionee Elife S plus and that has got everyone speaking in the town. Unveiled in November 2015, this smartphone really comes with a power punch of amazing specifications and sharp new design. There are new additions to the features in this phone along with the top of the line features that every smartphones promises to offer. The fact that Gionee has been kind to people not just by the high quality smartphones but by keeping the prices on the bar is the reason why it has enjoyed a wide acclamation from the masses. The phone comes in three different colour codes that is White (Gives a really smooth and elegant look.), Blue (Gives a nice sharp and trendy look.), Gold (It is my favourite of all which is lustrous and leaves a lasting impression.) These three shades adds to the striking form. It has a sturdy metallic frame which gives it a clean and sharp look. The display screen is 5.5 inch ...

Message anyone on Facebook

Hey Everyone today we are showing you how to send a message to anyone on facebook, even if he/she's not added in your friendlist. Of course,  you can click on the button "Message", but it will appear as "Message", not as Chat. First of all I'd like to give credits to - Le Boss ( here ). who shared this trick with us and we appreciate it. I- What we Need Facebook account For messaging Browser-Google Chrome or Mozzila firefox (works fine with both) II - How to Chat with Google Chrome So, that's basically very simple. 1 - Search someone you want to speak. The url would be something like this: Code: https://www.facebook.com/FacebookUsername I'll use that one : https://www.facebook.com/so.hotgirls 2 - Replace those "www" at the beginning by "graph". You will have something similar to this: 3 - You will take the value of "id" and "username". In that case the "id" is "179548569...