Závěrečná práce: Bc. Ján Masarik: Automating Bug Bounty
Diplomová práce
Automating Bug Bounty
Anotace
Táto práca predstavuje argumenty, ktoré stoja za rastúcou popularitou bug bounty programov a analyzuje časté zraniteľnosti s kritickým dopadom, ktorých nachádzanie je možno zautomatizovať. Vzhľadom na to, že nebolo nájdené vhodné existujúce riešenie pre podobnú automatizáciu, práca predstavuje jednoducho rozšíriteľný program zameraný na automatizáciu procesov v bug bugbounty. Osobitná pozornosť práce …více
Abstract
This thesis introduces the reasoning behind the increasing popularity of the bug bounty programs and analyzes the most common, impactful bugs whose discovery can be automated at scale. As there was no suitable existing solution for similar automation identified, the thesis introduces a new framework, specifically designed for the bug bounty automation use case. Particular attention of the thesis is …více
Zadání práce
In the theoretical part of the thesis, examples of a common class of bugs appearing in the bug bounty platforms will be introduced along with particular examples. Furthermore, benefits and differences with the traditional penetration testing approach will be covered along with a comparison of two major platforms from both, hacker's point of view, and the company's point of view (in cooperation with Kiwi.com).
This work may be inspired by closed-source BountyMachine [1].
21. 5. 2019 08:44, prof. RNDr. Václav Matyáš, M.Sc., Ph.D., učo 344
- Zadáno/změněno 20. 6. 2019 13:06, Alena Dvořáková
- Záznam založen 2. 5. 2019 09:33, Jana Zemanová, učo 9619
- Zveřejnit od 20. 5. 2019 09:56, Alena Dvořáková
- Práce převzata 20. 5. 2019 09:56, Alena Dvořáková
Práce na příbuzné téma
Seznam prací, které mají shodná klíčová slova.
-
DevOps Support for Continuous Release of Research Tools on Kubernetes Clusters
Viktoriia Martynovych, učo 531922 -
Post-Exploitation Tools for Limited Computing Environments
Bc. Ivan Kotora -
Security analysis of cryptocurrency hardware wallets
RNDr. Milan Šorf, učo 500362 -
Adapting a Web Application to Run on a Secure Cloud Platform
Ing. Andrej Valíček -
Porovnanie nástrojov na vynútenie politík pre Kubernetes klastre v podnikovom prostredí
Ing. Michal Čaniga -
Improving user experience in the sec-certs web tool
Ing. Martin Hofbauer -
Addressing Farmer–Herder Violence in Mali’s Mopti Region: A Policy Paper
Bc. Ema Logara -
Assessment of Public Trust in the Czech Armed Forces
Pavel Menšík




