Got paid for reporting another security bug today

awesomewebsites

Elite Member
Jr. Executive VIP
Jr. VIP
Joined
Nov 16, 2011
Messages
19,792
Reaction score
11,285
Not bad for an hour of work :
D1C3btE


If you have any questions regarding bug bounty programs or how to find bugs on websites, you can post below.
 
Congrats man. How would I get started in this field? I know programming and already an undergrad CS student.
 
Wow, That's some figures. First time am hearing of this. Off to Google!
 
Good payment op . Just want to know if there is a software that automatically look for bugs?
 
Wow really cool. Too bad there’s no way I could find a security bug, as I don’t have any skills in programming :(
 
Wow really cool. Too bad there’s no way I could find a security bug, as I don’t have any skills in programming :(
I also do not have much skills in programming. I just try to learn from already disclosed reports.
 
Interesting. When did you get started and how long till you earned something ?

Thanks for sharing
 
First of congrats. I know some people who make a living on this so I'd give you advice or maybe two.

I see most of the people saying it's good money, but I don't really agree with you.

You're reporting a bug to Quora which is probably worth 1 BILLION DOLLARS.

I'm sure they have a security company that deals with bugs and stuff and get paid more than that.

So what I'd suggest you do is MARKET YOURSELF. We are in a marketing forum after all.

Open a blog (assuming you don't have) and write for security tips for big companies. Be an industry expert and your hour will be much worth than that.

You can be the next Robert Herjavec.

I'm glad that we have people like you that are from different backgrounds. Best of luck to your career
 
Interesting. When did you get started and how long till you earned something ?

Thanks for sharing
After I started with this, I was able to find first bug in less than a month. But that whole month was dedicated to this work only. Therafter, I just search for bugs whenever I feel like and end up finding some.
 
Nice figures. How do you explain the kind of bug you ought to see on a site?
 
Congrats, Lately I am trying to find bugs on some website. But I don't know where to start & how to start.
 
First of congrats. I know some people who make a living on this so I'd give you advice or maybe two.

I see most of the people saying it's good money, but I don't really agree with you.

You're reporting a bug to Quora which is probably worth 1 BILLION DOLLARS.

I'm sure they have a security company that deals with bugs and stuff and get paid more than that.

So what I'd suggest you do is MARKET YOURSELF. We are in a marketing forum after all.

Open a blog (assuming you don't have) and write for security tips for big companies. Be an industry expert and your hour will be much worth than that.

You can be the next Robert Herjavec.

I'm glad that we have people like you that are from different backgrounds. Best of luck to your career

Awesome reply. Hope OP sees this and implements your suggestions.
 
First of congrats. I know some people who make a living on this so I'd give you advice or maybe two.

I see most of the people saying it's good money, but I don't really agree with you.

You're reporting a bug to Quora which is probably worth 1 BILLION DOLLARS.

I'm sure they have a security company that deals with bugs and stuff and get paid more than that.

So what I'd suggest you do is MARKET YOURSELF. We are in a marketing forum after all.

Open a blog (assuming you don't have) and write for security tips for big companies. Be an industry expert and your hour will be much worth than that.

You can be the next Robert Herjavec.

I'm glad that we have people like you that are from different backgrounds. Best of luck to your career

1 billion for a DoS ? lol.. not in your wildest dreams, not even 100k, not even 10k.
if it was remote code execution then we talk numbers but even then its < 100k for a bug on a single site.
would it be a remote code execution bug in a widely used server software such as apache or nginx, then you could get a million from exploit brokers that sell to governments, but still not billions.
 
First of congrats. I know some people who make a living on this so I'd give you advice or maybe two.

I see most of the people saying it's good money, but I don't really agree with you.

You're reporting a bug to Quora which is probably worth 1 BILLION DOLLARS.

I'm sure they have a security company that deals with bugs and stuff and get paid more than that.

So what I'd suggest you do is MARKET YOURSELF. We are in a marketing forum after all.

Open a blog (assuming you don't have) and write for security tips for big companies. Be an industry expert and your hour will be much worth than that.

You can be the next Robert Herjavec.

I'm glad that we have people like you that are from different backgrounds. Best of luck to your career
I have thought about this but didn't do it because I do not think I am an expert in this field yet. To do what you are recommending, I will have to do a lot of study in this field. Someone doing this full time will always be occupied as he will have to learn new technologies. However, on a small scale I may do this.

Nice figures. How do you explain the kind of bug you ought to see on a site?
Do you mean the category of bug ? Based on experience, one can differentiate.
 
1 billion for a DoS ? lol.. not in your wildest dreams, not even 100k, not even 10k.
if it was remote code execution then we talk numbers but even then its < 100k for a bug on a single site.
would it be a remote code execution bug in a widely used server software such as apache or nginx, then you could get a million from exploit brokers that sell to governments, but still not billions.

You got me wrong. I was saying Quora is worth 1 billion.
 
Back
Top