From 6a443a398dd6a39ac5a1a513c74e8144a72ab4d1 Mon Sep 17 00:00:00 2001 From: yaganub <35933803+yaganub@users.noreply.github.com> Date: Mon, 26 Nov 2018 15:09:04 -0500 Subject: [PATCH] Updated to clarify and add list of companies (#24220) * Updated to clarify and add list of companies Changed line 7 to read reward instead of money because not all companies offer monetary rewards. Added a section on notable companies and a link to a site that compiles a more extensive list of companies. * Update index.md --- guide/english/security/bug-bounties/index.md | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) diff --git a/guide/english/security/bug-bounties/index.md b/guide/english/security/bug-bounties/index.md index c6b146a93d..cbac4d4b27 100644 --- a/guide/english/security/bug-bounties/index.md +++ b/guide/english/security/bug-bounties/index.md @@ -4,7 +4,7 @@ title: Bug Bounties ## Bug Bounties -Bug bounties are programs that are set up by companies to encourage people to check their products for vulnerabilities. In return these companies offer cash prizes for the discovered vulnerabilities. +Bug bounties are programs that are set up by companies to encourage people to check their products for vulnerabilities. In return these companies offer rewards for reporting the discovered vulnerabilities. ### Benefits to bounty hunters @@ -17,3 +17,18 @@ The companies that sponsor these programs gain several benefits: - Many eyes on their product are more likely to find more bugs than the typical QA team - Only have to pay for results, not for the time spent trying to find bugs - Encourages people who find vulnerabilties to turn them over to the company and not to the black market. + +### Notable companies and organizations that offer bug bounties + +- Cisco +- Facebook +- Github +- Google +- Instagram +- Mastercard +- Microsoft +- Paypal +- Twitter +- Uber + +A more comprehensive list can be found at the Bugcrowd's Bug Bounty List - https://www.bugcrowd.com/bug-bounty-list/