Technology
HackerOne pays $20K to user who hacked its own platform
New Delhi, Dec 9
Facing an embarrassing situation, San Francisco-based HackerOne which is a vulnerability coordination and bug bounty platform and boasts of clients like Starbucks, Instagram, Goldman Sachs, Twitter and Zomato, has paid $20,000 to a user who exposed a vulnerability in its own bug bounty platform.
The vulnerability was exposed by a user with the handle called "haxta4ok00" who has now been paid $20,000 by HackerOne.
"A hacker had access for a short time to information relating to other programmes running on the HackerOne platform.
"Less than 5 per cent of HackerOne programmes were impacted, and those programmes were contacted within 24 hours of report receipt," HackerOne said in a statement this week.
The hacker, and HackerOne community member posted a report to the bug bounty platform: "I can read all reports @security and more programmes."
HackerOne responded: "We didn't find it necessary for you to have opened all the reports and pages in order to validate you had access to the account. Would you mind explaining why you did so to us?"
Haxta4ok00 said: "I did it to show the impact. I didn't mean any harm by it. I reported it to you at once. I was not sure that after the token substitution I would own all the rights. I apologise if I did anything wrong. But it was just a white hack."
In August this year, HackerOne revealed that hackers earned $21 million in just a year reporting vulnerabilities via various bug bounty opportunities as governments' efforts to fix malware increased a whopping 214 per cent globally.
Food delivery platform Zomato has paid more than $100,000 (over Rs 70 lakh) to 435 hackers to date for finding and fixing bugs on its platform.
With the help of HackerOne's bug bounty programme since July 2017, Zomato has successfully resolved 775 vulnerabilities report.
Hacker-powered security is a technique that utilises collaboration with the hacker community to find unknown security vulnerabilities and reduce security risk. Popular examples include bug bounty programmes and vulnerability disclosure policies.
The vulnerability was exposed by a user with the handle called "haxta4ok00" who has now been paid $20,000 by HackerOne.
"A hacker had access for a short time to information relating to other programmes running on the HackerOne platform.
"Less than 5 per cent of HackerOne programmes were impacted, and those programmes were contacted within 24 hours of report receipt," HackerOne said in a statement this week.
The hacker, and HackerOne community member posted a report to the bug bounty platform: "I can read all reports @security and more programmes."
HackerOne responded: "We didn't find it necessary for you to have opened all the reports and pages in order to validate you had access to the account. Would you mind explaining why you did so to us?"
Haxta4ok00 said: "I did it to show the impact. I didn't mean any harm by it. I reported it to you at once. I was not sure that after the token substitution I would own all the rights. I apologise if I did anything wrong. But it was just a white hack."
In August this year, HackerOne revealed that hackers earned $21 million in just a year reporting vulnerabilities via various bug bounty opportunities as governments' efforts to fix malware increased a whopping 214 per cent globally.
Food delivery platform Zomato has paid more than $100,000 (over Rs 70 lakh) to 435 hackers to date for finding and fixing bugs on its platform.
With the help of HackerOne's bug bounty programme since July 2017, Zomato has successfully resolved 775 vulnerabilities report.
Hacker-powered security is a technique that utilises collaboration with the hacker community to find unknown security vulnerabilities and reduce security risk. Popular examples include bug bounty programmes and vulnerability disclosure policies.
23 minutes ago
Piyush Goyal meets Canadian Minister Maninder Sidhu to seal trade pact soon
1 hour ago
Marathi film ‘Gondhal’ announced as India's official selection for 99th Academy Awards
1 hour ago
Friendship Cup a celebration of cricket, reflects strong India-Afghanistan bond: DDCA chief Jaitley
4 hours ago
ActBlue faces scrutiny over foreign donations
4 hours ago
Kwatra recalls leadership lesson from mentorship under Satya Nadella’s father
6 hours ago
Zee TV’s Sa Re Ga Ma Pa – The Original Icon of Singing Shows is Back with Its Grandest Season Yet; Will Also Stream on ZEE5
7 hours ago
Lust Stories 3 Review: Four Stories. Unusual Desires and Plenty of Surprises
7 hours ago
Joey King: Sandra Bullock's one of the nicest people I’ve ever met in my life
7 hours ago
Upendra’s first look from Teja Sajja's 'Zombie Reddy2 NXT LVL' released!
7 hours ago
Karan Johar and Varun Dhawan to host IIFA Awards 2027 in Abu Dhabi
7 hours ago
Sana Thampi opens up about her first collaboration with Kiran Rao for ‘Lust Stories 3’
7 hours ago
Nivin Pauly pens note of gratitude as his Bethlehem Kudumba Unit's collections go past the Rs 300 crore mark!
7 hours ago
Actor Nani on why he does not want people to call his films pan-Indian!
