Get Paid $$$ to find bugs


SUBMITTED BY: 2Gnizama

DATE: March 31, 2021, 1:29 p.m.

FORMAT: Text only

SIZE: 8.4 kB

HITS: 609

  1. 1) Intel
  2. Intel's bounty program mainly targets the company's hardware, firmware, and software.
  3. Limitations: It does not include recent acquisitions, the company's web infrastructure, third-party products, or anything relating to McAfee.
  4. Minimum Payout: Intel offers a minimum amount of $500 for finding bugs in their system.
  5. Maximum Payout: The Company pays $30,000 maximum for detecting critical bugs.
  6. Bounty Link: https://security-center.intel.com/BugBountyProgram.aspx
  7. 2) Yahoo
  8. Yahoo has its dedicated team that accepts vulnerability reports from security researchers and ethical hackers.
  9. Limitations: The Company does not offer any reward for finding bugs in yahoo.net, Yahoo 7 Yahoo Japan, Onwander and Yahoo operated Word press blogs.
  10. Minimum Payout: There is no set limit on Yahoo for minimum payout.
  11. Maximum Payout: Yahoo can pay $15000 for detecting important bugs in their system.
  12. Bounty Link:https://safety.yahoo.com/Security/REPORTING-ISSUES.html
  13. 3) Snapchat
  14. Snapchat security team reviews all vulnerability reports and acts upon them by responsible disclosure. The company, we will acknowledge your submission within 30 days.
  15. Minimum Payout: Snapchat will pay minimum $2000.
  16. Maximum Payout: Maximum they will pay is $15,000.
  17. Bounty Link:https://support.snapchat.com/en-US/i-need-help
  18. 4) Cisco
  19. Cisco encourages individuals or organization that are experiencing a product security issue to report them to the company.
  20. Minimum Payout: Cisco's minimum payout amount is $100.
  21. Maximum Payout: Company will give maximum $2,500 to finding serious vulnerabilities.
  22. Bounty Link: https://tools.cisco.com/security/center/resources/security_vulnerability_policy.html
  23. 5) Dropbox
  24. Dropbox bounty program allows security researchers to report bugs and vulnerabilities on the third party service HackerOne.
  25. Minimum Payout: The minimum amount paid is $12,167.
  26. Maximum Payout: The maximum amount offered is $32,768.
  27. Bounty Link: https://help.dropbox.com/accounts-billing/security/how-security-works
  28. 6) Apple
  29. When Apple first launched its bug bounty program it allowed just 24 security researchers. The framework then expanded to include more bug bounty hunters.
  30. The company will pay $100,000 to those who can extract data protected by Apple's Secure Enclave technology.
  31. Minimum Payout: There is no limited amount fixed by Apple Inc.
  32. Maximum payout: The highest bounty given by Apple is $200,000 for security issues affecting its firmware.
  33. Bounty Link: https://support.apple.com/en-au/HT201220
  34. 7) Facebook
  35. Under Facebook's bug bounty program users can report a security issue on Facebook, Instagram, Atlas, WhatsApp, etc.
  36. Limitations: There are a few security issues that the social networking platform considers out-of-bounds.
  37. Minimum Payout: Facebook will pay a minimum of $500 for a disclosed vulnerability.
  38. Maximum Payout: There is no upper limit fixed by Facebook for the Payout.
  39. Bounty Link: https://www.facebook.com/whitehat/
  40. 8) Google
  41. Every content in the .google.com, .blogger, youtube.com are open for Google's vulnerability rewards program.
  42. Limitations: This bounty program only covers design and implementation issues.
  43. Minimum Payout: Google will pay minimum $300 for finding security threads.
  44. Maximum Payout: Google will pay the highest bounty of $31.337 for normal Google applications.
  45. Bounty Link: https://www.google.com/about/appsecurity/reward-program/
  46. 9) Quora
  47. Quora offers Bug Bounty program to all users and researchers to find and report security vulnerabilities.
  48. Minimum Payout: Quora will pay minimum $100 for finding vulnerabilities on their site.
  49. Maximum Payout: Maximum payout offered by this site is $7000.
  50. Bounty Link: https://engineering.quora.com/Security-Bug-Bounty-Program
  51. 10) Mozilla
  52. Mozilla rewards for vulnerability discoveries by ethical hackers and security researchers.
  53. Limitations: The bounty is offered only for bugs in Mozilla services, such as Firefox, Thunderbird and other related applications and services.
  54. Minimum Payout: Minium amount given by Firefox is $500.
  55. Maximum Payout: The Company is paying a maximum of $5000.
  56. Bounty Link: https://www.mozilla.org/en-US/security/bug-bounty/
  57. 11) Microsoft
  58. Microsoft's current bug bounty program was officially launched on 23rd September 2014 and deals only with Online Services.
  59. Limitations: The bounty reward is only given for the critical and important vulnerabilities.
  60. Minimum Payout: Microsoft ready to pay $15,000 for finding critical bugs.
  61. Maximum Payout: Maximum amount can be $250,000.
  62. Bounty Link: https://technet.microsoft.com/en-us/library/dn425036.aspx
  63. 12) OpenSSL
  64. OpenSSL bounty allows you to report vulnerabilities using secure email (PGP Key). You can also report vulnerabilities to the OpenSSL Management Committee.
  65. Minimum Payout: The Company pays minimum bounty rewards of $500.
  66. Maximum Payout: The highest amount given by the company is $5000.
  67. Bounty Link: https://www.openssl.org/news/vulnerabilities.html
  68. 13) Vimeo
  69. Vimeo welcomes any security vulnerability reporting in their products as the company pays good rewards to that person.
  70. Minimum payout: The Company will pay minimum $500
  71. Maximum Payout: The maximum amount paid by this company is $5000.
  72. Bounty Link: https://vimeo.com/about/security
  73. 14) Apache
  74. Apache encourages ethical hackers to report security vulnerabilities to one of their private security mailing lists.
  75. Minimum payout: The minimum pay out amount given by Apache is $500.
  76. Maximum Payout: This Company can maximum give a reward of $3000.
  77. Bounty Link: https://www.apache.org/security/
  78. 15) Twitter
  79. Twitter allows security researchers and experts about possible security vulnerabilities in their services. The company encourages people to find bugs.
  80. Minimum Payout: Twitter is paying minimum $140 amount.
  81. Maximum Payout: Maximum amount pay by the company is $15000.
  82. Bounty Link: https://support.twitter.com/articles/477159
  83. 16) Avast
  84. Avast bounty program rewards ethical hackers and security researchers to report Remote code execution, Local privilege escalation, DOS, scanner bypass amongst other issues.
  85. Minimum Payout: Avast can pay you the minimum amount of $400.
  86. Maximum Payout: The maximum amount offered by the company is $10,000.
  87. Bounty Link: https://www.avast.com/bug-bounty
  88. 17) Paypal
  89. Payment gateway service Paypal also offers bug bounty programs for security researchers.
  90. Limitations:
  91. Vulnerabilities dependent upon social engineering techniques, Host Header
  92. Denial of service (DOS), User defined payload, Content spoofing without embedded links/HTM and Vulnerabilities which require a jailbroken mobile device, etc.
  93. Minimum Payout: Paypal can pay minimum $50 for finding security vulnerabilities in their system.
  94. Maximum Payout: Maximum payout amount given by Paypal is $10000.
  95. Bounty Link: https://hackerone.com/paypal
  96. 18) GitHub
  97. GitHub's runs bug bounty program since 2013. Every successful participant earned points for their vulnerability submissions depending on the severity.
  98. Limitation: The security researcher will receive that bounty only if they respect users' data and don't exploit any issue to produce an attack that could harm the integrity of GitHub's services or information.
  99. Minimum Payout: Github pays a minimum amount of $200 for finding bugs.
  100. Maximum Payout: Github can pay $10000 for finding critical bugs.
  101. Bounty Link: https://bounty.github.com/
  102. 19) Uber
  103. The vulnerability rewards program of Uber primarily focused on protecting the data of users and its employees.
  104. Minimum Payout: There is no predetermined minimum amount.
  105. Maximum Payout: Uber will pay you $10,000 for finding critical bug issues.
  106. Bounty Link: https://eng.uber.com/bug-bounty-map/
  107. 20) Magento
  108. Magneto bounty program allows you to report security vulnerabilities in Magneto software or websites.
  109. Limitations:
  110. Following security research is not eligible for the bounty
  111. Potential or actual denial of service of Magento applications and systems.
  112. Use of an exploit to view data without authorization.
  113. Automated/scripted testing of web forms
  114. Minimum Payout: Minimum payout amount for this is bounty program is $100.
  115. Maximum Payout: Magento is paying maximum $10,000 for finding critical bugs.
  116. Bounty Link: https://magento.com/security

comments powered by Disqus