diff --git a/README.md b/README.md index 26b20e9..f1be65e 100644 --- a/README.md +++ b/README.md @@ -40,6 +40,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B ### Platforms +- [intigriti](https://intigriti.com/) - [HackerOne](https://hackerone.com/) - [Bugcrowd](https://bugcrowd.com/) - [Cobalt](https://cobalt.io/) @@ -50,6 +51,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [FOSS Factory](http://www.fossfactory.org/) - [Synack](https://www.synack.com/) - [HackenProof](https://hackenproof.com/) +- [Detectify](https://cs.detectify.com/) ### Available Programs - [123Contact Form](http://www.123contactform.com/security-acknowledgements.htm) @@ -64,6 +66,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Airbnb](https://hackerone.com/airbnb) - [Algolia](https://hackerone.com/algolia) - [Altervista](http://en.altervista.org/feedback.php?who=feedback) +- [Altroconsumo](https://go.intigriti.com/altroconsumo) - [Amara](mailto:security@amara.org) - [Amazon Web Services](mailto:aws-security@amazon.com) - [Amazon.com](mailto:security@amazon.com) @@ -76,6 +79,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Apptentive](https://www.apptentive.com/contact) - [Aptible](mailto:security@aptible.com) - [Ardour](http://tracker.ardour.org/my_view_page.php) +- [Arkane](https://go.intigriti.com/arkanenetwork) - [ARM mbed](mailto:whitehat@polarssl.org) - [Asana](mailto:security@asana.com) - [ASP4all](mailto:support@asp4all.nl) @@ -89,6 +93,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [AwardWallet](https://cobalt.io/awardwallet) - [Badoo](https://corp.badoo.com/en/security/#send_bid) - [Barracuda](https://bugcrowd.com/barracuda) +- [Base](https://go.intigriti.com/base) - [Basecamp](mailto:security@basecamp.com) - [Beanstalk](https://wildbit.wufoo.com/forms/wildbit-security-response) - [BillGuard](https://cobalt.io/billguard) @@ -121,6 +126,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Bookfresh](https://hackerone.com/bookfresh) - [Box](mailto:security-reports@box.com) - [Braintree](mailto:security@braintreepayments.com) +- [Brussels Airlines](https://go.intigriti.com/brusselsairlines) - [BTC_sx](https://cobalt.io/btc-sx) - [Buffer](mailto:security@bufferapp.com) - [BX.in.th](https://cobalt.io/bx-in-th) @@ -155,6 +161,8 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [coins.ph](https://cobalt.io/coins-ph) - [Cointrader.net](https://cobalt.io/cointrader-net) - [Coinvoy](https://cobalt.io/coinvoy) +- [Collishop](https://go.intigriti.com/collishop) +- [Colruyt](https://go.intigriti.com/colruyt) - [Compose](mailto:security@compose.io) - [concrete5](https://hackerone.com/concrete5) - [Constant Contact](mailto:vulnerability@constantcontact.com) @@ -164,6 +172,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [cPanel](mailto:security@cpanel.net) - [cPaperless](mailto:support@cPaperless.com) - [Crix.io](https://cobalt.io/crixio) +- [Cross Border Fines](https://go.intigriti.com/crossborderfines) - [CrowdShield](https://crowdshield.com/bug-bounty-list.php?bug_bounty_program=crowdshield) - [Cryptocat](https://github.com/cryptocat/cryptocat/issues) - [Cupcake](mailto:security@cupcake.io) @@ -171,6 +180,8 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Cylance](https://hackerone.com/cylance) - [Dato Capital](mailto:security%40datocapital.com) - [Detectify](mailto:disclosure@detectify.com) +- [De Volkskrant](https://go.intigriti.com/devolkskrant) +- [Delen Private Bank](https://go.intigriti.com/delen) - [DigitalOcean](mailto:security@digitalocean.com) - [DigitalSellz](https://hackerone.com/digitalsellz) - [Django](https://hackerone.com/django) @@ -178,11 +189,14 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [DoSomething](https://cobalt.io/dosomething) - [DPD](mailto:security@dpd.zendesk.com) - [Dragon King](https://hackenproof.com/neverdie/dragon-king) +- [Dreambaby](https://go.intigriti.com/dreamland) +- [Dreamland](https://go.intigriti.com/dream) - [Dropbox](https://hackerone.com/dropbox) - [Dropbox Acquisitions](https://hackerone.com/dropbox-acquisitions) - [Drupal](https://www.drupal.org/node/101494) - [eBay](http://pages.ebay.com/securitycenter/Researchers.html) - [Eclipse](mailto:security@eclipse.org) +- [eHealth Hub VZN KUL](https://go.intigriti.com/ehealthhubvznkul) - [EMC](mailto:security_alert@emc.com) - [Enano](mailto:security@enanocms.org) - [Engine Yard](mailto:security@engineyard.com) @@ -194,6 +208,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Event Espresso](http://eventespresso.com/report-a-security-vulnerability) - [Everitoken](https://hackenproof.com/everitoken/everitoken-blockchain) - [Evernote](mailto:security@evernote.com) +- [EURid](https://go.intigriti.com/eurid) - [Expatistan](mailto:gerardo@expatistan.com) - [ExpressionEngine](https://hackerone.com/expressionengine) - [Ezbob](https://cobalt.io/ezbob) @@ -224,6 +239,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [GlobaLeaks](https://hackerone.com/globaleaks) - [Google PRP](mailto:security-patches@google.com) - [Google VRP](https://www.google.com/about/appsecurity/reward-program/index.html) +- [Grammarly](https://hackerone.com/grammarly) - [Gratipay](https://hackerone.com/gratipay) - [GreenAddress](https://cobalt.io/greenaddress) - [Greenhouse.io](https://hackerone.com/greenhouse) @@ -239,6 +255,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Huawei](mailto:psirt@huawei.com) - [Hubdia](https://hackerone.com/hubdia) - [Humble Bundle](https://bugcrowd.com/humblebundle) +- [IAM KU Leuven](https://go.intigriti.com/kuleuvenlogin) - [Ian Dunn](https://hackerone.com/iandunn-projects) - [IBM](https://www.ibm.com/scripts/contact/contact/us/en/security_vulnerabilities) - [ICEcoder](https://bugcrowd.com/icecoder) @@ -255,6 +272,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [IRCCloud](https://hackerone.com/irccloud) - [itBit Exchange](https://hackerone.com/itbit) - [ITRP](mailto:security@itrp.com) +- [itsme](https://go.intigriti.com/itsme) - [joola.io](https://hackerone.com/joola-io) - [Joomla](http://vel.joomla.org/submit-vel) - [JRuby](mailto:security@jruby.org) @@ -267,6 +285,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Keybase](https://hackerone.com/keybase) - [Khan Academy](https://hackerone.com/khanacademy) - [Kraken](mailto:bugbounty@kraken.com) +- [Kinepolis](https://go.intigriti.com/kinepolis) - [Kuna](https://hackenproof.com/kuna/kuna-crypto-exchange) - [Lancor Income](https://cobalt.io/lancor-income) - [LastPass](mailto:security@lastpass.com) @@ -293,6 +312,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [ManageBGL](https://cobalt.io/managebgl) - [ManageWP](mailto:security@managewp.com) - [MapLogin](https://hackerone.com/maplogin) +- [Marietje Schaake](https://go.intigriti.com/marietjeschaake) - [Marktplatts](https://hackerone.com/marktplaats) - [Mavenlink](https://hackerone.com/mavenlink) - [Maximum](https://hackerone.com/maximum) @@ -303,6 +323,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [meXBT](https://cobalt.io/mexbt) - [Microsoft](mailto:secure@microsoft.com) - [Mimecast](mailto:disclosure@mimecast.com) +- [Mobile Vikings](https://go.intigriti.com/mobilevikings) - [Mobile Vikings](https://hackerone.com/mobilevikings) - [Modus CSR](mailto:security@moduscsr.com) - [MoneyBird](mailto:security@moneybird.com) @@ -311,7 +332,6 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Motorola Solutions](mailto:security@motorolasolutions.com) - [Mozilla](https://www.mozilla.org/en-US/security/bug-bounty/) - [mynxt.info](https://cobalt.io/mynxt-info) -- [Natures Organics](mailto:ict@naturesorganics.com.au) - [NCSC](mailto:cert@ncsc.nl) - [Nearby Live](https://hackerone.com/nearby) - [Nest](mailto:security@nest.com) @@ -319,6 +339,8 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Neverdie Smart Contract](https://hackenproof.com/neverdie/neverdie-smart-contract) - [Neverdie Web](https://hackenproof.com/neverdie/neverdie-web) - [Nexmo](https://cobalt.io/nexmo) +- [Nexuzhealth(https://go.intigriti.com/nexushealth) +- [Nexuzhealth Web PACS](https://go.intigriti.com/nexuzhealthwebpacs) - [Nginx](https://hackerone.com/ibb-nginx) - [Nitrous](mailto:security@nitrous.io) - [Nokia Networks](mailto:security-alert@nokia.com) @@ -329,6 +351,8 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [OKCoin](https://cobalt.io/okcoin) - [OkCupid](https://hackerone.com/okcupid) - [Olark](mailto:security@olark.com) +- [OneSpan Mobile](https://go.intigriti.com/vascomobileproducts) +- [OneSpan Server Products](https://go.intigriti.com/vascoserver-sideproducts) - [Opal Cryptocurrency](https://cobalt.io/opal-cryptocurrency) - [Openfolio](https://hackerone.com/openfolio) - [OpenSSL](https://hackerone.com/ibb-openssl) @@ -392,6 +416,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Secret](https://hackerone.com/secret) - [Secure Works](mailto:security@secureworks.com) - [Sellfy](http://docs.sellfy.com/contact) +- [Sentiance](https://go.intigriti.com/sentiance) - [ServiceRocket](https://bugcrowd.com/servicerocket) - [ShareLaTeX](mailto:team@sharelatex.com) - [Sherpany](https://cobalt.io/sherpany) @@ -402,12 +427,14 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [SiteGround](mailto:responsible-disclosure@siteground.com) - [Skoodat](mailto:security@skoodat.com) - [Skrill](https://cobalt.io/skrill) +- [Skyscanner](https://bugcrowd.com/skyscanner) - [Slack](https://hackerone.com/slack) - [Snapchat](https://hackerone.com/snapchat) - [Snappy](mailto:security@userscape.com) - [Sonatype](mailto:security@sonatype.com) - [Sony](https://secure.sony.net/form) - [SoundCloud](https://scsecurity.freshdesk.com/support/tickets/new) +- [Spaargids](https://go.intigriti.com/spaargids) - [SpectroCoin](https://cobalt.io/spectrocoin) - [Spendbitcoins](https://cobalt.io/spendbitcoins) - [SplashID](https://bugcrowd.com/splashid) @@ -418,15 +445,20 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Square Open Source](https://hackerone.com/square-open-source) - [StatusPage](https://bugcrowd.com/sunrise) - [StopTheHacker](https://hackerone.com/stopthehacker) +- [Student Assessment System](https://go.intigriti.com/printscan) +- [Studio 100](https://go.intigriti.com/studio100) - [Subledger](https://cobalt.io/subledger) - [Subrosa](https://cobalt.io/subrosa) - [Sucuri](https://hackerone.com/sucuri) +- [Suivo](https://go.intigriti.com/suivoweb) - [Symantec](mailto:secure@symantec.com) - [Taptalk](https://hackerone.com/taptalk) - [Tarsnap](mailto:cperciva@tarsnap.com) - [TeamUnify](mailto:security@teamunify.com) - [Tele2](mailto:beveiligingsmeldpunt@tele2.com) - [Telekom](mailto:cert@telekom.de?subject=bug_bounty) +- [Telenet](https://go.intigriti.com/telenet) +- [Test-Aankoop](https://go.intigriti.com/testaankoop) - [The Internet](https://hackerone.com/internet) - [The Mastercoin Foundation](https://cobalt.io/the-mastercoin-foundation) - [ThisData](https://hackerone.com/thisdata) @@ -434,6 +466,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [ToyTalk](https://hackerone.com/toytalk) - [Trello](https://hackerone.com/trello) - [Tuenti](http://corporate.tuenti.com/en/contact/security) +- [Tweakers](https://go.intigriti.com/tweakers) - [Twilio](https://bugcrowd.com/twilio) - [Twitch](mailto:security@twitch.tv) - [Twitter](https://hackerone.com/twitter) @@ -464,6 +497,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Windthorst ISD](http://www.windthorstisd.net/BugReport.cfm) - [withinsecurity](https://hackerone.com/withinsecurity) - [WizeHive](mailto:security@wizehive.com) +- [Woorank](https://go.intigriti.com/woorank) - [WordPoints](https://hackerone.com/wordpoints) - [Wordware](https://cobalt.io/wordware) - [WP API](https://hackerone.com/wp-api) @@ -485,6 +519,9 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Zopim](https://hackerone.com/zopim) - [Zynga](mailto:whitehat@zynga.com) +## Aggregators + +- [BountyHQ](https://bountyhq.secapps.com/) ## License