<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; hacking-for-money</title>
	<atom:link href="http://www.darknet.org.uk/tag/hacking-for-money/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Facebook To Start Paying Bug Bounties</title>
		<link>http://www.darknet.org.uk/2011/07/facebook-to-start-paying-bug-bounties/</link>
		<comments>http://www.darknet.org.uk/2011/07/facebook-to-start-paying-bug-bounties/#comments</comments>
		<pubDate>Fri, 29 Jul 2011 18:36:59 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[bug bounty]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[facebook bounty]]></category>
		<category><![CDATA[facebook bug bounty]]></category>
		<category><![CDATA[facebook exploit]]></category>
		<category><![CDATA[facebook pays hackers]]></category>
		<category><![CDATA[facebook security]]></category>
		<category><![CDATA[facebook vulnerability]]></category>
		<category><![CDATA[hacking-facebook]]></category>
		<category><![CDATA[hacking-for-money]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3158</guid>
		<description><![CDATA[We&#8217;ve covered various stories about companies offering hackers and security researchers bounties for giving them working exploits for their software/website etc. Early runners in the game were &#8211; Google Willing To Pay Bounty For Chrome Browser Bugs Now, 2 years down the road, Facebook has decided it&#8217;s a good idea to offer up a $500 [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve covered various stories about companies offering hackers and security researchers bounties for giving them working exploits for their software/website etc. Early runners in the game were &#8211; <a href="http://www.darknet.org.uk/2010/02/google-willing-to-pay-bounty-for-chrome-browser-bugs/">Google Willing To Pay Bounty For Chrome Browser Bugs</a></p>
<p>Now, 2 years down the road, <a href="http://www.darknet.org.uk/tag/facebook/">Facebook</a> has decided it&#8217;s a good idea to offer up a $500 bounty for exploits reported to the Facebook security team.</p>
<p>They are claiming they will pay out larger amounts for &#8216;truly significant&#8217; bugs, but they aren&#8217;t qualifying that claim with any guidelines or amounts.</p>
<blockquote><p>Facebook is going to pay hackers to find problems with its website &#8212; just so long as they report them to Facebook&#8217;s security team first.</p>
<p>The company is following Google and Mozilla in launching a Web &#8220;Bug Bounty&#8221; program. For security related bugs &#8212; cross site scripting flaws, for example &#8212; the company will pay a base rate of $500. If they&#8217;re truly significant flaws Facebook will pay more, though company executives won&#8217;t say how much.</p>
<p>&#8220;In the past we&#8217;ve focused on name recognition by putting their name up on our page, sending schwag out and using this an avenue for interviews and the recruiting process,&#8221; said Alex Rice, Facebook&#8217;s product security lead. &#8220;We&#8217;re extending that now to start paying out monetary rewards.&#8221;</p>
<p>On Friday, Facebook will launch a new Whitehat hacking portal where researchers can sign up for the program and report bugs.</p>
<p>Many hackers go public with the software and website flaws they find to gain prestige. Finding an important bug on a widely used website such as Facebook can help make a journeyman hacker&#8217;s career, and going to the press with the issue can make him &#8212; or her &#8212; famous. </p></blockquote>
<p>They have always credited people who made discovered of insecurities on the <a href="http://www.darknet.org.uk/tag/facebook/">Facebook</a> platform and gifted them with t-shirts and other goodies, but this is the first move Facebook has made towards paying for exploits.</p>
<p>It is true though, finding a serious bug in a prestigious web property like Facebook could make someone famous overnight. I would like to see more bounty programs and those bounty programs paying out larger amounts.</p>
<p>Although I have to say I don&#8217;t believe a flaw in a social network would be worth that much on the black market (as opposed to say a <a href="http://www.darknet.org.uk/tag/zero-day/">zero-day</a> in the latest version of Apache).</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>But talking about the issue before Facebook has had a chance to patch it, can be risky for Facebook users. In recent years, other companies have started these bug bounty programs to encourage hackers to keep quiet about the problems they find until they are patched.</p>
<p>Google pays between $500 and $3,133.70, depending on the severity of the flaw.</p>
<p>Google started to pay for browser bugs in early 2010, and then in November it expanded the program to cover bugs in its Web properties too.</p>
<p>The Web bug bounty program has helped Google uncover a lot of programming errors in the past eight months, most of which have been in Google&#8217;s lesser-known products, a company spokesman said this week.</p>
<p>Google sees its Web program as a big success. &#8220;We&#8217;re very happy with the success of our vulnerability reward program so far. We&#8217;ve already given out $300,000 and have seen a variety of interesting bugs,&#8221; the spokesman said in an e-mail message.</p>
<p>Facebook&#8217;s security team already engages in a lot of dialogue between security researchers and its own programmers. The company is contacted between 30 and 50 times each week by hackers. Their information leads to an average of about one to three &#8220;actionable bugs,&#8221; per week, Rice said. Most of these are cross-site scripting or cross-site request forgery issues. These are both very common Web programming errors that could be abused by scammers and cybercrooks to rip off Facebook users.</p></blockquote>
<p><a href="http://www.darknet.org.uk/tag/google/">Google</a> have given out over $300,000 since they started their program in 2010 &#8211; initially it was only for <a href="http://www.darknet.org.uk/tag/chrome/">Chrome</a> bugs &#8211; but they expanded it to cover all of their web properties and they&#8217;ve reaped the rewards by being able to fix all kinds of issues.</p>
<p>I foresee Facebook not having to pay out so much, the site is fairly closed and it&#8217;s not as expansive as the Google empire. Plus they don&#8217;t have any kind of actual software offering like Chrome.</p>
<p>It&#8217;s an interesting program though and I hope it leads to <a href="http://www.darknet.org.uk/tag/facebook/">Facebook</a> becoming more secure.</p>
<p>Source: <a href="http://www.networkworld.com/news/2011/072911-facebook-to-pay-hackers-for.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Facebook+To+Start+Paying+Bug+Bounties+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3158+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/07/facebook-to-start-paying-bug-bounties/&amp;t=Facebook+To+Start+Paying+Bug+Bounties" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/07/facebook-to-start-paying-bug-bounties/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/07/facebook-to-start-paying-bug-bounties/&amp;title=Facebook+To+Start+Paying+Bug+Bounties" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/07/facebook-to-start-paying-bug-bounties/&amp;title=Facebook+To+Start+Paying+Bug+Bounties" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/07/facebook-to-start-paying-bug-bounties/&amp;title=Facebook+To+Start+Paying+Bug+Bounties" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/07/facebook-to-start-paying-bug-bounties/&amp;title=Facebook+To+Start+Paying+Bug+Bounties" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F07%2Ffacebook-to-start-paying-bug-bounties%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/07/facebook-to-start-paying-bug-bounties/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>2007 Hacker Reverse Engineering Challenge</title>
		<link>http://www.darknet.org.uk/2007/09/2007-hacker-reverse-engineering-challenge/</link>
		<comments>http://www.darknet.org.uk/2007/09/2007-hacker-reverse-engineering-challenge/#comments</comments>
		<pubDate>Mon, 03 Sep 2007 06:19:42 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Events/Cons]]></category>
		<category><![CDATA[2007]]></category>
		<category><![CDATA[hacker-challenge]]></category>
		<category><![CDATA[hacker-challenge-2007]]></category>
		<category><![CDATA[hackerchallenge]]></category>
		<category><![CDATA[hacking-competition]]></category>
		<category><![CDATA[hacking-contest]]></category>
		<category><![CDATA[hacking-for-money]]></category>
		<category><![CDATA[money]]></category>
		<category><![CDATA[prizes]]></category>
		<category><![CDATA[win-prizes]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/09/2007-hacker-reverse-engineering-challenge/</guid>
		<description><![CDATA[Similar to the Hacker Challenge in 2006, it is being run by a U.S. company performing security testing and security metric research. The purpose of this challenge is to evaluate the effectiveness of software protections. The results of this effort will be used to improve protection measures. There will be three distinct, yet related, phases [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Similar to the <a href="http://www.darknet.org.uk/2006/12/linux-reverse-engineering-hacker-challenge/">Hacker Challenge in 2006</a>, it is being run by a U.S. company performing security testing and security metric research. The purpose of this challenge is to evaluate the effectiveness of software protections. The results of this effort will be used to improve protection measures.</p>
<p>There will be three distinct, yet related, phases to this contest. The first phase will be a hacker challenge, for which anyone can register to participate. The second stage of the contest will be a market (based on the Phase 1 challenge). Participation in this second phase will be by invitation only, based on performance in the first phase. The third phase of the contest will be a more challenging hacker challenge; this phase may or may not be invitation-only. There are opportunities to earn money in all three phases of the contest.</p>
<p>All file downloads and uploads necessary for the contest will be possible after the participant has logged in. The market will also be visible, at the appropriate time, after logging in.</p>
<p>You can read more here.</p>
<p><a href="http://www.hackerchallenge.org/">http://www.hackerchallenge.org/</a></p>
<p>All payments are in U.S. dollars, and will be made anonymously via PayPal with prizes up to $50,000USD for the three phases.</p>
<p></p>
<p>You can register <a href="http://www.hackerchallenge.org/register">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=2007+Hacker+Reverse+Engineering+Challenge+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D674+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/09/2007-hacker-reverse-engineering-challenge/&amp;t=2007+Hacker+Reverse+Engineering+Challenge" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/09/2007-hacker-reverse-engineering-challenge/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/09/2007-hacker-reverse-engineering-challenge/&amp;title=2007+Hacker+Reverse+Engineering+Challenge" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/09/2007-hacker-reverse-engineering-challenge/&amp;title=2007+Hacker+Reverse+Engineering+Challenge" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/09/2007-hacker-reverse-engineering-challenge/&amp;title=2007+Hacker+Reverse+Engineering+Challenge" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/09/2007-hacker-reverse-engineering-challenge/&amp;title=2007+Hacker+Reverse+Engineering+Challenge" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F09%2F2007-hacker-reverse-engineering-challenge%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/09/2007-hacker-reverse-engineering-challenge/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

