Microsoft Bounty Programs | MSRC
文章推薦指數: 80 %
Microsoft Bug Bounty Program. Microsoft strongly believes close partnerships with researchers make customers more secure. Security researchers play an ... Skiptomaincontent MicrosoftBugBountyProgram Microsoftstronglybelievesclosepartnershipswithresearchersmakecustomersmoresecure.Securityresearchersplayanintegralroleintheecosystembydiscoveringvulnerabilitiesmissedinthesoftwaredevelopmentprocess.Eachyearwepartnertogethertobetterprotectbillionsofcustomersworldwide. IfyouareasecurityresearcherthathasfoundavulnerabilityinaMicrosoftproduct,service,ordevicewewanttohearfromyou.Ifyourvulnerabilityreportaffectsaproductorservicethatiswithinscopeofoneofourbountyprogramsbelow,youmayreceiveabountyawardaccordingtotheprogramdescriptions.Evenifitisnotcoveredunderanexistingbountyprogram,wewillpubliclyacknowledgeyourcontributionswhenwefixthevulnerability.Allvulnerabilitysubmissionsarecountedin ourResearcherRecognitionProgramandleaderboard,eveniftheydonotqualifyforbountyaward. Clickheretosubmitasecurityvulnerability TheMicrosoftBugBountyProgramsaresubjecttothelegaltermsandconditionsoutlinedhere,andourbountySafeHarborpolicy. Letthehuntbegin! Ourbugbountyprogramsaredividedby technologyareathoughtheygenerallyhavethesamehighlevelrequirements: Wewanttoawardyou Wearelookingfornew Avoidharmtocustomerdata Followco-ordvulnerabilitydisclosure ProgramName Startdate LastUpdated Enddate Eligibleentries BountyRange MicrosoftAzure 2014-09-23 2021-10-18 Ongoing VulnerabilityreportsonMicrosoftAzurecloudservices Upto$60,000USD MicrosoftIdentity 2018-07-17 2019-10-23 Ongoing VulnerabilityreportsonIdentityservices,includingMicrosoftAccount,AzureActiveDirectory,orselectOpenIDstandards. Upto$100,000USD Xbox 2020-01-30 2020-01-30 Ongoing VulnerabilityreportsontheXboxLivenetwork and services Upto$20,000USD M365 2014-09-23 2019-08-05 Ongoing VulnerabilityreportsonapplicableMicrosoftcloudservices,includingOffice365 Upto$20,000USD MicrosoftAzureDevOpsServices 2019-01-17 2019-01-17 Ongoing VulnerabilityreportsonapplicableMicrosoftAzureDevOpsServices Upto$20,000USD MicrosoftDynamics365andPowerPlatform 2019-07-17 2022-04-14 Ongoing VulnerabilityreportsonapplicableMicrosoftDynamics365 andPowerPlatformapplications Upto$20,000USD Microsoft.NET 2016-09-01 2020-11-20 Ongoing Vulnerabilityreportson.NETCoreandASP.NETCoreRTMandfuturebuilds(seelinkforprogramdetails) Upto$15,000USD ProgramName StartDate LastUpdated EndDate EligibleEntries BountyRange MicrosoftHyper-V 2017-05-31 2020-04-13 Ongoing Criticalremotecodeexecution,informationdisclosureanddenialofservicesvulnerabilitiesinHyper-V Upto$250,000USD MicrosoftWindowsInsiderPreview 2017-07-26 2020-08-27 Ongoing Criticalandimportantvulnerabilitiesin WindowsInsiderPreview Upto$100,000USD MicrosoftApplications andOn-PremisesServers 2021-03-24 2022-04-05 Ongoing CriticalandimportantvulnerabilitiesinMicrosoftApplicationsandOn-PremisesServers Upto$30,000USD WindowsDefenderApplicationGuard 2017-07-26 2017-07-26 Ongoing Criticalvulnerabilitiesin WindowsDefenderApplicationGuard Upto$30,000USD MicrosoftEdge(Chromium-based) 2019-08-20 2021-10-21 Ongoing Critical,important,andmoderatevulnerabilitiesinMicrosoftEdge(Chromium-based)Dev,Beta,andStable channels Upto$30,000USD OfficeInsider 2017-03-15 2018-12-07 Ongoing Vulnerabilitieson OfficeInsider Upto$15,000USD ElectionGuard 2019-10-18 2021-03-31 Ongoing VulnerabilitiesinElectionGuard Upto$15,000USD ProgramName StartDate LastUpdated EndDate EligibleEntries BountyRange MitigationBypassandBountyforDefense 2013-06-26 2018-10-02 Ongoing NovelexploitationtechniquesagainstprotectionsbuiltintothelatestversionoftheWindowsoperatingsystem.Additionally,defensiveideasthataccompanyaMitigationBypasssubmission. Upto$100,000USD(plusuptoanadditional$100,000) Grant:MicrosoftIdentity 2020-01-09 2020-04-09 Ongoing This projectgrant awardsupto$75,000USD forapprovedresearchproposalsthatimprovethesecurityoftheMicrosoftIdentitysolutionsinnewwaysforbothConsumers(MicrosoftAccount)andEnterprise(AzureActiveDirectory). Upto$75,000USD SIKECryptographicChallenge 2021-06-09 2021-06-09 Ongoing Thischallengeawardsupto$50,000USDforsolutionsthatbreaktheSIKEalgorithmfortwosetsoftoyparameters. Upto$50,000USD Wehavepulledtogetheradditionalresourcestohelpyouunderstandourbountyprogramofferingsandevenhelpyougetstartedonthepathortohigherpayouts.Wetrulyviewthisasacollaborativepartnershipwiththesecuritycommunity.Yoursuccessinthisprogramhelpsfurtherourcustomer’ssecurityandtheecosystem. FrequentlyAskedQuestions WhattoExpectWhenReportingVulnerabilitiestoMicrosoft ExampleofHighQualityReports ResearcherRecognitionProgram MicrosoftBountyLegalSafeHarbor WindowsSecurityServicingCriteria DirectoryofAzureServices MicrosoftDocumentationforendusers,developers,andITprofessionals MicrosoftSecurityResearch&DefenseBlog HackerOne’sHacker101training BugcrowdUniversity SomesubmissiontypesaregenerallynoteligibleforMicrosoftbountyawards.Pleaserefertoourbountyprogramsforadditionalinformationoneligiblesubmission,vulnerability,orattackmethods. Tooloutput Socialengineering
延伸文章資訊
- 1Google Bug Hunters
Welcome to Google's Bug Hunting community, learn more about hunting & reporting bugs you've found...
- 2Bug Bounty Program - Facebook
Bug Bounty Program. Info. Thanks. Hacker Plus Program. Integrity Safeguards. Education. Payout Gu...
- 3熱門Bug Bounty線上課程- 更新於[2022 October] - Udemy
Bug Bounty 與下列類別相關: IT 與軟體網路與安全性. 215840位學習者 ... Ethical Hacking / Penetration Testing & Bug Boun...
- 4從過去四年Bug Bounty Program,Synology 學到了什麼?
隨著企業資安意識抬頭,近年Bug Bounty Program 依舊是產業熱烈討論的議題,許多科技公司例如蘋果、Google、微軟、LINE 等大廠都透過這項計畫與白帽駭 ...
- 5Public Bug Bounty Program List - Bugcrowd
The most comprehensive, up-to-date crowdsourced bug bounty list and vulnerability disclosure prog...