Category: Bug Hunters

#NDH16 : Knowledge is power

In 2018, for the first time, La Nuit du Hack takes place at La Cité des Sciences et de l’Industrie  in Paris.

YesWeHack is proud to be one of the numerous Platinum Sponsors of #NDH16 ! We are longing for having Fun and meeting you Folks in this temple of science.

Photo by HackerzVoice

Photo by HZV

Science

In this age of panic where the powers in place are trying to mitigate “fake news” (well… let’s say more precisely propaganda or misinformation), La Cité des Sciences et de l’Industrie symbolizes knowledge in many ways, Science is one the best allies to counterattack lies and conspiracy theories.

As a famous place in Paris, La Cité des Sciences et de l’Industrie provides through three levels : a 900 seat amphitheater, 2000m2 of exhibition area and one space called the « Loft » with its 1000m2 fully dedicated to hacktivities and games orchestrated by the HZV’s Team <3

Gravity, Density & Fun

So for this edition, La Nuit du Hack is going to deliver its thoroughness and richness with : 14 talks, 10 workshops, 6 Challenges, 1 Private CTF, On Site Bug Bounties and a Confessional .

Read More

OVH Bug Bounty RetEx by Vincent Malguy

As OVH bug bounty manager from March 2016 to March 2018, Vincent Malguy, through this interview, delivers his return of experience to share some tips with people who wonder how to set up and manage a program.

***

The genesis

In the early 2010’s, many companies in the IT sector like Facebook or Google started to launch bug bounty programs and within OVH this appeared as an obvious need. However, it took time to frame the project and to meet all the operational conditions to take the leap.

In 2015, when I was recruited by OVH, it was time to put in place all the bricks to calmly launch a bug bounty.

Back in the day, we identified two issues: the issue of vulnerability export and the legal complexity when paying rewards.

Of course, we evaluated the possibility of launching it without external help but we quickly gave up the idea because it is not our core business.

In any case since the beginning, it has been clear in our minds that a real bug bounty program is, in the long run, a program open to a wide audience.

In January 2016, we met with Korben and Freeman. They presented YesWeWack’s roadmap to launch the first European bug bounty platform.

The timing was perfect and we decided together to launch OVH’s public program on the occasion of “la Nuit du Hack” in June 2016.

Private phase

In this exercise we have the support of the management and technical teams.

Based on that internal mobilization, we started to carry out an additional audit on the initial scope in order to ensure its maturity. We then worked with the communications, legal and accounting teams. Once these prerequisites were gathered and validated, with YesWeHack, we started with a 1 month private window.

Read More

SaXX, number one of Bounty Factory’s all time ranking.

This month, we publish an interview with one of the best researchers of our  Bounty Factory called SaXX who is only 27 years old.

In the all time ranking, SaXX culminates in the first place and he intends to defend his ranking well. Like Rafael Nadal, SaXX never gives up and works hard to exercise his passion with his true mischievous side!

1. Where did you get your nickname?

Well, that’s a question a lot of people ask.
I only tell the genesis of this nickname in certain circles.

2. What’s your background?

I have a career path that some would describe as classic. I had a BAC S (maths specialization) then a BTS IG at that period of time. After the BTS, I didn’t really know what to do so I let myself be tempted by an Information Systems Management school in Lorient – France.

Read More

Portrait of a bug hunter : Ylujion

ylujionYesWeHack is glad to introduce you to its best hunters performing on BountyFactory.io

This week, it’s @Ylujion‘s turn, Check his portrait below !

Read More

Goals and means of a bug bounty hunter.

These days, Bug bounty Hunters are trending within the IT security ecosystem, but very few articles deal with the DNA of a Bug Bounty Hunter.

At Bountyfactory.io, we consider Bug Hunters have to respect and fit legal frameworks and norms.

AS a bug hunter please find below the goals you should be driven by :

Read More

Powered by WordPress & Theme by Anders Norén