From d1017e1827742d8ca7470c58e445c97f1c6417f0 Mon Sep 17 00:00:00 2001 From: Leo Date: Wed, 21 Nov 2018 09:55:55 +0100 Subject: [PATCH 1/7] Added Detectify crowdsource to platforms --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index a8959dc..71aead2 100644 --- a/README.md +++ b/README.md @@ -49,6 +49,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [FreedomSponsors](https://freedomsponsors.org/) - [FOSS Factory](http://www.fossfactory.org/) - [Synack](https://www.synack.com/) +- [Detectify](https://cs.detectify.com/) ### Available Programs - [123Contact Form](http://www.123contactform.com/security-acknowledgements.htm) From 00b2ac3065e2e824a394ccc40fea6d380ee976e3 Mon Sep 17 00:00:00 2001 From: Phillip Smith Date: Wed, 12 Dec 2018 17:05:08 +1100 Subject: [PATCH 2/7] Remove "Natures Organics" Natures Organics does not have, and has never had, a bug bounty program. Not sure what data this list was compiled from. --- README.md | 1 - 1 file changed, 1 deletion(-) diff --git a/README.md b/README.md index a8959dc..28f91c3 100644 --- a/README.md +++ b/README.md @@ -306,7 +306,6 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Motorola Solutions](mailto:security@motorolasolutions.com) - [Mozilla](https://www.mozilla.org/en-US/security/bug-bounty/) - [mynxt.info](https://cobalt.io/mynxt-info) -- [Natures Organics](mailto:ict@naturesorganics.com.au) - [NCSC](mailto:cert@ncsc.nl) - [Nearby Live](https://hackerone.com/nearby) - [Nest](mailto:security@nest.com) From e331c118c4e9066120fa932494b53bd2dbf377a7 Mon Sep 17 00:00:00 2001 From: Vladimir Metnew Date: Thu, 10 Jan 2019 15:21:27 +0200 Subject: [PATCH 3/7] feat(available_programs): add Grammarly --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index a8959dc..8435440 100644 --- a/README.md +++ b/README.md @@ -221,6 +221,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [GlobaLeaks](https://hackerone.com/globaleaks) - [Google PRP](mailto:security-patches@google.com) - [Google VRP](https://www.google.com/about/appsecurity/reward-program/index.html) +- [Grammarly](https://hackerone.com/grammarly) - [Gratipay](https://hackerone.com/gratipay) - [GreenAddress](https://cobalt.io/greenaddress) - [Greenhouse.io](https://hackerone.com/greenhouse) From 01703177eb07aa6e284f5bab87f325dd83d3260e Mon Sep 17 00:00:00 2001 From: Arne Schoonvliet Date: Tue, 15 Jan 2019 08:57:08 +0100 Subject: [PATCH 4/7] Update README.md Added intigriti as platfrom --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index a8959dc..d480d60 100644 --- a/README.md +++ b/README.md @@ -40,6 +40,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B ### Platforms +- [intigriti](https://intigriti.com/) - [HackerOne](https://hackerone.com/) - [Bugcrowd](https://bugcrowd.com/) - [Cobalt](https://cobalt.io/) From 5723fb00ba97de85ea1c1586edb5bb3fe5562379 Mon Sep 17 00:00:00 2001 From: Arne Schoonvliet Date: Tue, 15 Jan 2019 09:41:30 +0100 Subject: [PATCH 5/7] Update README.md Added all public programs of intigriti --- README.md | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) diff --git a/README.md b/README.md index d480d60..b56e098 100644 --- a/README.md +++ b/README.md @@ -64,6 +64,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Airbnb](https://hackerone.com/airbnb) - [Algolia](https://hackerone.com/algolia) - [Altervista](http://en.altervista.org/feedback.php?who=feedback) +- [Altroconsumo](https://go.intigriti.com/altroconsumo) - [Amara](mailto:security@amara.org) - [Amazon Web Services](mailto:aws-security@amazon.com) - [Amazon.com](mailto:security@amazon.com) @@ -76,6 +77,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Apptentive](https://www.apptentive.com/contact) - [Aptible](mailto:security@aptible.com) - [Ardour](http://tracker.ardour.org/my_view_page.php) +- [Arkane](https://go.intigriti.com/arkanenetwork) - [ARM mbed](mailto:whitehat@polarssl.org) - [Asana](mailto:security@asana.com) - [ASP4all](mailto:support@asp4all.nl) @@ -89,6 +91,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [AwardWallet](https://cobalt.io/awardwallet) - [Badoo](https://corp.badoo.com/en/security/#send_bid) - [Barracuda](https://bugcrowd.com/barracuda) +- [Base](https://go.intigriti.com/base) - [Basecamp](mailto:security@basecamp.com) - [Beanstalk](https://wildbit.wufoo.com/forms/wildbit-security-response) - [BillGuard](https://cobalt.io/billguard) @@ -121,6 +124,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Bookfresh](https://hackerone.com/bookfresh) - [Box](mailto:security-reports@box.com) - [Braintree](mailto:security@braintreepayments.com) +- [Brussels Airlines](https://go.intigriti.com/brusselsairlines) - [BTC_sx](https://cobalt.io/btc-sx) - [Buffer](mailto:security@bufferapp.com) - [BX.in.th](https://cobalt.io/bx-in-th) @@ -155,6 +159,8 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [coins.ph](https://cobalt.io/coins-ph) - [Cointrader.net](https://cobalt.io/cointrader-net) - [Coinvoy](https://cobalt.io/coinvoy) +- [Collishop](https://go.intigriti.com/collishop) +- [Colruyt](https://go.intigriti.com/colruyt) - [Compose](mailto:security@compose.io) - [concrete5](https://hackerone.com/concrete5) - [Constant Contact](mailto:vulnerability@constantcontact.com) @@ -164,6 +170,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [cPanel](mailto:security@cpanel.net) - [cPaperless](mailto:support@cPaperless.com) - [Crix.io](https://cobalt.io/crixio) +- [Cross Border Fines](https://go.intigriti.com/crossborderfines) - [CrowdShield](https://crowdshield.com/bug-bounty-list.php?bug_bounty_program=crowdshield) - [Cryptocat](https://github.com/cryptocat/cryptocat/issues) - [Cupcake](mailto:security@cupcake.io) @@ -171,17 +178,22 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Cylance](https://hackerone.com/cylance) - [Dato Capital](mailto:security%40datocapital.com) - [Detectify](mailto:disclosure@detectify.com) +- [De Volkskrant](https://go.intigriti.com/devolkskrant) +- [Delen Private Bank](https://go.intigriti.com/delen) - [DigitalOcean](mailto:security@digitalocean.com) - [DigitalSellz](https://hackerone.com/digitalsellz) - [Django](https://hackerone.com/django) - [Doorkeeper](mailto:info@doorkeeper.jp) - [DoSomething](https://cobalt.io/dosomething) - [DPD](mailto:security@dpd.zendesk.com) +- [Dreambaby](https://go.intigriti.com/dreamland) +- [Dreamland](https://go.intigriti.com/dream) - [Dropbox](https://hackerone.com/dropbox) - [Dropbox Acquisitions](https://hackerone.com/dropbox-acquisitions) - [Drupal](https://www.drupal.org/node/101494) - [eBay](http://pages.ebay.com/securitycenter/Researchers.html) - [Eclipse](mailto:security@eclipse.org) +- [eHealth Hub VZN KUL](https://go.intigriti.com/ehealthhubvznkul) - [EMC](mailto:security_alert@emc.com) - [Enano](mailto:security@enanocms.org) - [Engine Yard](mailto:security@engineyard.com) @@ -192,6 +204,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [EVE](mailto:security@ccpgames.com) - [Event Espresso](http://eventespresso.com/report-a-security-vulnerability) - [Evernote](mailto:security@evernote.com) +- [EURid](https://go.intigriti.com/eurid) - [Expatistan](mailto:gerardo@expatistan.com) - [ExpressionEngine](https://hackerone.com/expressionengine) - [Ezbob](https://cobalt.io/ezbob) @@ -236,6 +249,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Huawei](mailto:psirt@huawei.com) - [Hubdia](https://hackerone.com/hubdia) - [Humble Bundle](https://bugcrowd.com/humblebundle) +- [IAM KU Leuven](https://go.intigriti.com/kuleuvenlogin) - [Ian Dunn](https://hackerone.com/iandunn-projects) - [IBM](https://www.ibm.com/scripts/contact/contact/us/en/security_vulnerabilities) - [ICEcoder](https://bugcrowd.com/icecoder) @@ -252,6 +266,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [IRCCloud](https://hackerone.com/irccloud) - [itBit Exchange](https://hackerone.com/itbit) - [ITRP](mailto:security@itrp.com) +- [itsme](https://go.intigriti.com/itsme) - [joola.io](https://hackerone.com/joola-io) - [Joomla](http://vel.joomla.org/submit-vel) - [JRuby](mailto:security@jruby.org) @@ -264,6 +279,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Keybase](https://hackerone.com/keybase) - [Khan Academy](https://hackerone.com/khanacademy) - [Kraken](mailto:bugbounty@kraken.com) +- [Kinepolis](https://go.intigriti.com/kinepolis) - [Lancor Income](https://cobalt.io/lancor-income) - [LastPass](mailto:security@lastpass.com) - [LaunchKey](mailto:security@launchkey.com) @@ -289,6 +305,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [ManageBGL](https://cobalt.io/managebgl) - [ManageWP](mailto:security@managewp.com) - [MapLogin](https://hackerone.com/maplogin) +- [Marietje Schaake](https://go.intigriti.com/marietjeschaake) - [Marktplatts](https://hackerone.com/marktplaats) - [Mavenlink](https://hackerone.com/mavenlink) - [Maximum](https://hackerone.com/maximum) @@ -299,6 +316,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [meXBT](https://cobalt.io/mexbt) - [Microsoft](mailto:secure@microsoft.com) - [Mimecast](mailto:disclosure@mimecast.com) +- [Mobile Vikings](https://go.intigriti.com/mobilevikings) - [Mobile Vikings](https://hackerone.com/mobilevikings) - [Modus CSR](mailto:security@moduscsr.com) - [MoneyBird](mailto:security@moneybird.com) @@ -313,6 +331,8 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Nest](mailto:security@nest.com) - [Netflix](mailto:security-report@netflix.com) - [Nexmo](https://cobalt.io/nexmo) +- [Nexuzhealth(https://go.intigriti.com/nexushealth) +- [Nexuzhealth Web PACS](https://go.intigriti.com/nexuzhealthwebpacs) - [Nginx](https://hackerone.com/ibb-nginx) - [Nitrous](mailto:security@nitrous.io) - [Nokia Networks](mailto:security-alert@nokia.com) @@ -323,6 +343,8 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [OKCoin](https://cobalt.io/okcoin) - [OkCupid](https://hackerone.com/okcupid) - [Olark](mailto:security@olark.com) +- [OneSpan Mobile](https://go.intigriti.com/vascomobileproducts) +- [OneSpan Server Products](https://go.intigriti.com/vascoserver-sideproducts) - [Opal Cryptocurrency](https://cobalt.io/opal-cryptocurrency) - [Openfolio](https://hackerone.com/openfolio) - [OpenSSL](https://hackerone.com/ibb-openssl) @@ -386,6 +408,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Secret](https://hackerone.com/secret) - [Secure Works](mailto:security@secureworks.com) - [Sellfy](http://docs.sellfy.com/contact) +- [Sentiance](https://go.intigriti.com/sentiance) - [ServiceRocket](https://bugcrowd.com/servicerocket) - [ShareLaTeX](mailto:team@sharelatex.com) - [Sherpany](https://cobalt.io/sherpany) @@ -402,6 +425,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Sonatype](mailto:security@sonatype.com) - [Sony](https://secure.sony.net/form) - [SoundCloud](https://scsecurity.freshdesk.com/support/tickets/new) +- [Spaargids](https://go.intigriti.com/spaargids) - [SpectroCoin](https://cobalt.io/spectrocoin) - [Spendbitcoins](https://cobalt.io/spendbitcoins) - [SplashID](https://bugcrowd.com/splashid) @@ -412,15 +436,20 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Square Open Source](https://hackerone.com/square-open-source) - [StatusPage](https://bugcrowd.com/sunrise) - [StopTheHacker](https://hackerone.com/stopthehacker) +- [Student Assessment System](https://go.intigriti.com/printscan) +- [Studio 100](https://go.intigriti.com/studio100) - [Subledger](https://cobalt.io/subledger) - [Subrosa](https://cobalt.io/subrosa) - [Sucuri](https://hackerone.com/sucuri) +- [Suivo](https://go.intigriti.com/suivoweb) - [Symantec](mailto:secure@symantec.com) - [Taptalk](https://hackerone.com/taptalk) - [Tarsnap](mailto:cperciva@tarsnap.com) - [TeamUnify](mailto:security@teamunify.com) - [Tele2](mailto:beveiligingsmeldpunt@tele2.com) - [Telekom](mailto:cert@telekom.de?subject=bug_bounty) +- [Telenet](https://go.intigriti.com/telenet) +- [Test-Aankoop](https://go.intigriti.com/testaankoop) - [The Internet](https://hackerone.com/internet) - [The Mastercoin Foundation](https://cobalt.io/the-mastercoin-foundation) - [ThisData](https://hackerone.com/thisdata) @@ -428,6 +457,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [ToyTalk](https://hackerone.com/toytalk) - [Trello](https://hackerone.com/trello) - [Tuenti](http://corporate.tuenti.com/en/contact/security) +- [Tweakers](https://go.intigriti.com/tweakers) - [Twilio](https://bugcrowd.com/twilio) - [Twitch](mailto:security@twitch.tv) - [Twitter](https://hackerone.com/twitter) @@ -456,6 +486,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Windthorst ISD](http://www.windthorstisd.net/BugReport.cfm) - [withinsecurity](https://hackerone.com/withinsecurity) - [WizeHive](mailto:security@wizehive.com) +- [Woorank](https://go.intigriti.com/woorank) - [WordPoints](https://hackerone.com/wordpoints) - [Wordware](https://cobalt.io/wordware) - [WP API](https://hackerone.com/wp-api) From 949ee5859e594f076ccb11b822bdc406052ceccd Mon Sep 17 00:00:00 2001 From: Nacho Rasche Date: Mon, 21 Jan 2019 13:21:14 +0100 Subject: [PATCH 6/7] Add link to skyscanner programme --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index a8959dc..7a60668 100644 --- a/README.md +++ b/README.md @@ -395,6 +395,7 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [SiteGround](mailto:responsible-disclosure@siteground.com) - [Skoodat](mailto:security@skoodat.com) - [Skrill](https://cobalt.io/skrill) +- [Skyscanner](https://bugcrowd.com/skyscanner) - [Slack](https://hackerone.com/slack) - [Snapchat](https://hackerone.com/snapchat) - [Snappy](mailto:security@userscape.com) From ac873ee949754c14fc359f6b091c1ac2eb6e0df6 Mon Sep 17 00:00:00 2001 From: pdparchitect Date: Tue, 12 Mar 2019 12:03:00 +0000 Subject: [PATCH 7/7] Added BountyHQ BountyHQ aggregates useful data from all bounty programs for free so it is a good source of information to get started in any bug-bounty. --- README.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/README.md b/README.md index a8959dc..38deff4 100644 --- a/README.md +++ b/README.md @@ -476,6 +476,9 @@ A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug B - [Zopim](https://hackerone.com/zopim) - [Zynga](mailto:whitehat@zynga.com) +## Aggregators + +- [BountyHQ](https://bountyhq.secapps.com/) ## License