1
1

00:00:00,240  -->  00:00:01,860
<v Instructor>In this lesson, we're going to discuss</v>
2

2

00:00:01,860  -->  00:00:03,480
bug bounties and how they can be used
3

3

00:00:03,480  -->  00:00:05,430
in the cybersecurity industry.
4

4

00:00:05,430  -->  00:00:07,680
Now, a bug bounty program is a way for companies
5

5

00:00:07,680  -->  00:00:10,020
to crowdsource security testing of their software,
6

6

00:00:10,020  -->  00:00:12,000
services, and applications.
7

7

00:00:12,000  -->  00:00:14,100
By offering financial compensation rewards
8

8

00:00:14,100  -->  00:00:15,900
to ethical hackers and security researchers
9

9

00:00:15,900  -->  00:00:17,880
who discover and report vulnerabilities,
10

10

00:00:17,880  -->  00:00:19,320
organizations and companies
11

11

00:00:19,320  -->  00:00:21,990
can better identify and address potential security issues
12

12

00:00:21,990  -->  00:00:24,780
before they can be exploited by malicious actors.
13

13

00:00:24,780  -->  00:00:27,120
Now, when a company creates a bug bounty program,
14

14

00:00:27,120  -->  00:00:29,100
they typically set out the scope of the program
15

15

00:00:29,100  -->  00:00:31,440
which includes the specific systems and applications
16

16

00:00:31,440  -->  00:00:33,300
that are in scope for that test
17

17

00:00:33,300  -->  00:00:34,770
as well as the rules and guidelines
18

18

00:00:34,770  -->  00:00:37,860
for how and when vulnerabilities need to be reported.
19

19

00:00:37,860  -->  00:00:40,050
Companies can also establish the reward system
20

20

00:00:40,050  -->  00:00:42,150
which can include financial compensation,
21

21

00:00:42,150  -->  00:00:44,640
swag, recognition or something else
22

22

00:00:44,640  -->  00:00:46,710
that helps to incentivize security researchers
23

23

00:00:46,710  -->  00:00:47,940
and ethical hackers
24

24

00:00:47,940  -->  00:00:50,460
to participate in their bug bounty program.
25

25

00:00:50,460  -->  00:00:52,380
Participation in a bug bounty program
26

26

00:00:52,380  -->  00:00:54,390
can take many different forms.
27

27

00:00:54,390  -->  00:00:56,880
As a cybersecurity professional working for a company,
28

28

00:00:56,880  -->  00:00:58,320
you can participate by identifying
29

29

00:00:58,320  -->  00:00:59,430
and reporting vulnerabilities
30

30

00:00:59,430  -->  00:01:01,860
inside your own internal systems and software,
31

31

00:01:01,860  -->  00:01:02,880
which can then help the company
32

32

00:01:02,880  -->  00:01:04,470
improve their security posture.
33

33

00:01:04,470  -->  00:01:06,115
Additionally, some companies will also allow
34

34

00:01:06,115  -->  00:01:08,430
people from outside of their organization
35

35

00:01:08,430  -->  00:01:11,400
to participate in bug bounties as third party testers.
36

36

00:01:11,400  -->  00:01:12,690
And this helps 'em to identify
37

37

00:01:12,690  -->  00:01:14,550
the most critical types of vulnerabilities,
38

38

00:01:14,550  -->  00:01:16,800
which are those publicly facing vulnerabilities
39

39

00:01:16,800  -->  00:01:19,200
on their websites and other software.
40

40

00:01:19,200  -->  00:01:20,550
Individuals can also work
41

41

00:01:20,550  -->  00:01:23,010
as independent penetration testers or researchers
42

42

00:01:23,010  -->  00:01:26,070
as they're participating in these third party bug bounties.
43

43

00:01:26,070  -->  00:01:27,630
They can then use the bug bounty program
44

44

00:01:27,630  -->  00:01:29,700
as an opportunity to showcase their skills
45

45

00:01:29,700  -->  00:01:31,920
and earn recognition within the cybersecurity community
46

46

00:01:31,920  -->  00:01:34,710
as well as earning rewards and money for their findings
47

47

00:01:34,710  -->  00:01:37,590
and helping to make the internet a more secure place.
48

48

00:01:37,590  -->  00:01:39,780
Now, if you want to participate in a bug bounty program
49

49

00:01:39,780  -->  00:01:41,640
as an individual penetration tester
50

50

00:01:41,640  -->  00:01:43,230
or cybersecurity analyst,
51

51

00:01:43,230  -->  00:01:44,157
you're normally going to have to research
52

52

00:01:44,157  -->  00:01:45,600
the scope of the program
53

53

00:01:45,600  -->  00:01:48,270
and identify vulnerabilities in the systems and applications
54

54

00:01:48,270  -->  00:01:50,670
that are within the scope of that program.
55

55

00:01:50,670  -->  00:01:53,160
These vulnerabilities will then be reported to the company
56

56

00:01:53,160  -->  00:01:54,450
through a designated channel,
57

57

00:01:54,450  -->  00:01:56,520
such as an online form or an email address
58

58

00:01:56,520  -->  00:01:58,260
to collect your responses.
59

59

00:01:58,260  -->  00:01:59,430
It's really important that you follow
60

60

00:01:59,430  -->  00:02:01,650
the guidelines and rules provided by the company
61

61

00:02:01,650  -->  00:02:04,470
to avoid any misunderstanding or breaching of their terms
62

62

00:02:04,470  -->  00:02:06,330
of their bug bounty program.
63

63

00:02:06,330  -->  00:02:08,520
If you're participating in a bug bounty program,
64

64

00:02:08,520  -->  00:02:10,080
it's always important to approach testing
65

65

00:02:10,080  -->  00:02:12,030
in a responsible and ethical manner
66

66

00:02:12,030  -->  00:02:14,130
and avoid causing any kind of harm or disruption
67

67

00:02:14,130  -->  00:02:16,560
to the systems, applications, or services
68

68

00:02:16,560  -->  00:02:18,300
of the target organization.
69

69

00:02:18,300  -->  00:02:20,790
It's also important to obtain any necessary permissions,
70

70

00:02:20,790  -->  00:02:23,160
including legal agreements and non-disclosure agreements
71

71

00:02:23,160  -->  00:02:24,210
that you may need to sign
72

72

00:02:24,210  -->  00:02:26,970
before you begin doing your penetration testing.
73

73

00:02:26,970  -->  00:02:28,410
If you're working as an organization
74

74

00:02:28,410  -->  00:02:30,030
that wants to set up a bug bounty,
75

75

00:02:30,030  -->  00:02:31,680
it's important that you have a robust system
76

76

00:02:31,680  -->  00:02:34,590
for tracking, triaging, and remediating vulnerabilities
77

77

00:02:34,590  -->  00:02:36,900
that are found through your bug bounty program.
78

78

00:02:36,900  -->  00:02:38,296
This process can include steps such as
79

79

00:02:38,296  -->  00:02:41,070
replicating and verifying reported vulnerabilities,
80

80

00:02:41,070  -->  00:02:42,300
prioritizing vulnerabilities
81

81

00:02:42,300  -->  00:02:44,460
based on their severity and potential impact,
82

82

00:02:44,460  -->  00:02:46,560
and developing and implementing fixes.
83

83

00:02:46,560  -->  00:02:48,780
Remember, in general, it's important for you
84

84

00:02:48,780  -->  00:02:50,730
to register with the company ahead of time
85

85

00:02:50,730  -->  00:02:53,490
if you're going to participate in their bug bounty program.
86

86

00:02:53,490  -->  00:02:55,110
By registering, you're now considered
87

87

00:02:55,110  -->  00:02:57,660
to be an ethical hacker under their bug bounty program
88

88

00:02:57,660  -->  00:02:59,490
and not considered to be a malicious attacker
89

89

00:02:59,490  -->  00:03:01,620
who's trying to exploit their systems without permission,
90

90

00:03:01,620  -->  00:03:03,210
which would be considered a crime
91

91

00:03:03,210  -->  00:03:05,400
and you want to avoid any kind of legal repercussions.
92

92

00:03:05,400  -->  00:03:06,810
So, it's always important to ensure
93

93

00:03:06,810  -->  00:03:08,580
you're registered properly with the company
94

94

00:03:08,580  -->  00:03:10,530
before you begin testing their systems.
