Уровень 0 · материалов: 4
В кластер входят документы, описывающие обнаружение конкретных уязвимостей в технологиях и процесс взаимодействия с программами по поиску ошибок.
Общие признаки: критические ошибки безопасности, взаимодействие с исследователями безопасности, программы Bug Bounty, технические недостатки приложений
Группа выше: Bug bounty и раскрытие уязвимостей
Смысл: The text serves as a technical case study demonstrating that even highly popular applications can have simple security flaws and highlights the frustrations of security researchers dealing with inadequate bug bounty programs.
A security researcher discovered a critical XSS vulnerability in Telegram Web that could lead to full account takeover or RCE, but received a disproportionately low reward of 500 euros.
Смысл: The text illustrates that even simple, unintentional interactions can reveal critical security flaws in high-end technology, highlighting the fallibility of biometric security and the importance of bug bounty programs.
A father earned $1,380 after his 9-month-old daughter accidentally discovered a way to bypass the fingerprint lock on a Samsung Galaxy A30.
Смысл: The text exposes critical security vulnerabilities in Badoo's account management system and criticizes the company's dismissive attitude toward security researchers during their Bug Bounty program.
An independent researcher used Google Dorks to access Badoo accounts and expose registration flaws, which the company repeatedly dismissed as non-vulnerabilities.
Смысл: The main idea is to transparently share the results of a bug bounty program to improve the platform's security and engage the cybersecurity community. It demonstrates that even large-scale projects can have critical logic and configuration errors that are easily exploitable if not properly audited.
Badoo shares the interim results of its vulnerability contest, detailing critical bugs found in credit purchases, profile management, and CSRF protections.