|
|
|
|
|
by rixrax
2669 days ago
|
|
Have you thought of integrating some form of exploitability analysis[0][1] for the crashes|etc. fuzzing locates? So let's say I upload some FOSS project and end-up finding some crashes|potential vulnerabilities. Have you considered some sort of tie-in|integration to bug bounty programs so that I could get a small pay-out without having to go through the trouble of figuring out how exploitable a given crash might be, and more importantly to actually have to deal with trying to get the attention of the project? [0] https://www.microsoft.com/security/blog/2013/06/13/exploitab...
[1] https://github.com/jfoote/exploitable |
|
We've been thinking about the best way to use Fuzzbuzz to benefit the OSS/bug hunting community, and the integration idea is a great one. We're also providing free plans with extra CPU power for security researchers & bounty hunters.