GithubHelp home page GithubHelp logo

wangtielei / advisories Goto Github PK

View Code? Open in Web Editor NEW

This project forked from ssd-secure-disclosure/advisories

0.0 1.0 0.0 8.05 MB

SSD Secure Disclosure Advisories

License: Other

C++ 7.79% C 88.04% Assembly 3.58% Objective-C 0.51% PHP 0.03% Shell 0.06%

advisories's Introduction

SSD Secure Disclosure

SSD Secure Disclosure

SSD helps security researchers turn their skills in uncovering security vulnerabilities into a career. Designed by researchers, for researchers, SSD provides the fast response and support needed to get zero-day vulnerabilities responsibly reported to vendors and to get researchers the compensation they deserve. We help researchers get to the bottom of vulnerabilities affecting major operating systems, software or devices.

The SSD Community

As part of our vulnerability disclosure program we have established a community of researchers. We believe in long-term investment in this group and we provide the tools, education and knowledge they need to find more vulnerabilities and advanced attack vectors and discover innovative ways to exploit them.

We sponsor researcher’s workshops, courses, software licenses, hardware and conference attendance.

We are always looking for new researchers to join our community. That’s why we are promoting our “Friend Bring Friend” program. When you refer us a new researcher that starts working with us on Operating systems / Mobile / Web Browsers – you get 10,000$ USD / For other vulnerabilities – you get 1,000$ USD

As another way to support the international community we sponsor security conferences around the world – from Black Hat USA to community conferences such as DefCamp Romania. We publish vulnerability technical information in our blog (https://ssd-disclosure.com/index.php/advisories), on Twitter (@SecuriTeam_SSD) and in vendor advisories. We also give lectures and host hacking competitions at international security conferences.

In 2018 we sponsored and some of our researchers attended: OffensiveCon Hack In The Box Zer0con CanSec

Table of Contents

Advisories


Q&A

  • How much can I earn from working with you? The amount paid depends on two different variables:

    • How widespread is the software/hardware? Popular products typically reach higher amounts.
    • How critical is the vulnerability? For example, if you find an unauthenticated arbitrary code execution vulnerability, you would be paid substantially more than for a Cross Site Scripting vulnerability.
  • What if I want to stay anonymous?

    • Fine by us! A lot of our researchers choose to stay anonymous.
  • What is your policy regarding privacy and confidentiality of researcher’s information?

    • We take the privacy of researchers very seriously and do not disclose to any third party (including to customers) any personal information about researchers such as names, aliases, email addresses, bank details, or any other personal or confidential information.
  • What is the difference between SSD and Bug Bounties or other programs?

    • Financially:
      • We pay more than bug bounty programs.
      • If a vendor doesn’t have a bug bounty program – we are still interested in acquiring the vulnerability and reporting it to the vendor.
      • We believe researchers need to get paid for their effort and we are willing to offer higher rewards.
    • Administratively:
      • We will handle all the reporting process.
      • We will publish your research and attribute it per your instructions.
  • How do I submit my questions or research?


Contact

Reach us out at one of the following places:


Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

advisories's People

Contributors

ssd-orin avatar ssd-yuvalk avatar ssd-disclosure avatar

Watchers

James Cloos avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.