Доклад Ильи Агеева "Bounty-программа в Badoo сказ о том, как хакеры нас на уязвимости проверяли"

Embed Size (px)

DESCRIPTION

Доклад с Security Meetup

Citation preview

  • 1. Bounty- Badoo , #SecurityMeetUp

2. ?- - > 220 - ~ 50 - ~ 3000 - > 100 - > 30 3. - - - - - - (PCI DSS)- , , 4. - - - - - - (PCI DSS)- , , - 5. - - - -XSS- - 6. - 5 , - - 2000 7. 1 - - ~ 500 - ~ 50 - ~ 150 / / - > 50 - > - CSRF 8. 9. 10. Badoo- (BSI-13): Asd: 5Misconfiguration (BSI-12): whitebureau: 5CSRF (BSI-44): chipik: 4 11. ?- - -CSRF- :) 12. - - - - - 13. google-groupsemailformDevRelJury Development 14. JIRAemailformJIRA validation, Jury Developmentauto-emails 15. 2- - - - bugcrowd 16. 2- - - ~ 870 - ~ 50 - > 30 - > 20 17. 18. comet (BSI-329): maxxarts: Android- (addJavascriptInterface) (BSI-601): secure.doggy.lin: 2 Android- (BSI-600): secure.doggy.lin: 2 19. - , - - 20. - ()- / 21. ?http://corp.badoo.com/securityemail: [email protected]: http://habrahabr.ru/company/badoo/blog/facebook: https://www.facebook.com/BadooMoscowtwitter: https://twitter.com/BadooDev