--- title: "Zohar Shachar -- Bug Bounty from Both Sides" url: https://appsecpodcast.com/zohar-shachar-bug-bounty-from-both-sides/ date: 2023-04-03 duration_seconds: 2187 guests: ["Zohar Shachar"] topics: ["Security Testing", "Vulnerabilities and Exploits"] audio: https://www.buzzsprout.com/1730684/episodes/12578893-zohar-shachar-bug-bounty-from-both-sides.mp3 video: https://www.youtube.com/watch?v=PV5bqU-Rq6U transcript: true --- # Zohar Shachar -- Bug Bounty from Both Sides *April 3, 2023 · 36 min* with [Zohar Shachar](https://appsecpodcast.com/guests/zohar-shachar/) on [Security Testing](https://appsecpodcast.com/topics/security-testing/), [Vulnerabilities and Exploits](https://appsecpodcast.com/topics/vulnerabilities/) [Audio](https://www.buzzsprout.com/1730684/episodes/12578893-zohar-shachar-bug-bounty-from-both-sides.mp3) · [Video](https://www.youtube.com/watch?v=PV5bqU-Rq6U) ## Show notes Zohar Shachar joins us to discuss the bug bounty process from both sides. Zohar has spent time as a bug bounty hunter and shares wisdom on avoiding bug bounty-causing issues for your AppSec posture. We hope you enjoy this conversation with... Zohar spent time as a bug bounty hunter and shares wisdom on avoiding bug bounty causing issues for your application security posture. Keep security top of mind with continuous application security training for your developers. Security Journey offers bite-sized lessons with hands-on interactive training for all roles in the SDLC. Give your admins the ability to use pre-built or custom training paths with easy-to-use tracking and reporting. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Zohar Shachar joins us to discuss the bug bounty process from both sides of the equation. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Zohar Shachar: → [HackerOne](https://www.hackerone.com/) → [Google Abuse Vulnerability Reward Program](https://bughunters.google.com/about/rules/google-friends/5238081279623168/abuse-vulnerability-reward-program-rules) Mentioned in this episode: → [HackerOne](https://www.hackerone.com/) → [Google Abuse Vulnerability Reward Program](https://bughunters.google.com/about/rules/google-friends/5238081279623168/abuse-vulnerability-reward-program-rules) → [Enso Security](https://enso.security/) → [Aquia](https://www.aquia.us/) Chapters: 00:00 Meet Zohar Shachar: Bug Bounty from Both Sides 02:06 Let's get after it here. Super excited to have Zohar Shachar 05:42 Yeah. So I do have a question for you in regards 07:12 There is a lesson learned there, right 14:20 On the side of the researcher then, because I've heard other 17:57 You think about bug bounty versus pen testing, as since you're 21:01 Here's the million-dollar question. If you could only do one, what 24:42 Imagine if somebody invented a new service. It's lack of denial 28:24 Yeah. What are some other tips that you can offer to 33:58 That almost seems like a key takeaway, but I'll ask anyway ## Transcript *5,719 words · assemblyai* **0:00 Chris Romeo:** Zohar Shachar joins us to discuss the bug bounty process from both sides of the equation. Zohar spent time as a bug bounty hunter and shares wisdom on avoiding bug bounty causing issues for your application security posture. We hope you enjoy this conversation with Zohar Shachar. **0:19** Keep security top of mind with continuous application security training for your developers. Security Journey offers bite-sized lessons with hands-on interactive training for all roles in the SDLC. Give your admins the ability to use pre-built or custom training paths with easy-to-use tracking and reporting. Visit securityjourney.com to see our solution today. **0:41 Chris Romeo:** Hey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I'm the CEO of Curve Ventures, and I am also happy to be joined by my good friend Robert Hurlbut. Hey Robert. Hey Chris. Yeah, Robert Hurlbut, and I'm with Acquia and helping them as a principal application security architect and threat modeling lead. And, uh, really interesting topic that we're going to be talking about today. Yeah. And as I understand, in a few years, we'll have to refer to Robert as Dr. Earl Butt. That is, Robert recently enrolled in a— is that a PhD program in cybersecurity? A PhD research program, yes. Okay. So, wow, I'm going to have to call you doctor. So then, but one little bit of advice, if you're on an airplane and they come over the loudspeaker and they say, is there a doctor on the plane? They don't mean— They don't mean me. What you're offering to society there. **1:54** No. **1:54 Chris Romeo:** They're wanting a medical doctor who can probably save somebody. So— **1:57 Zohar Shachar:** Great advice. **1:58 Chris Romeo:** Just in case. In case you were— I'll repeat it again in a few years just in case, you know, like everything else I do. **2:04 Zohar Shachar:** But all right. **2:05 Chris Romeo:** So, let's get after it here. Super excited to have Zohar Shachar with us today. Zohar did a talk at OWASP Dublin here just a few months ago. It's called Don't Let Bug Bounty Kill Your Application Security Posture. And so, that's going to be the focus of our conversation today. We'll put a link in the show notes to the YouTube clip or the YouTube recording of Zohar's talk in Dublin. But we're going to talk about this same kind of topic today and see where we land. But first, we have to hear Zohar's security origin story before we even talk bug bounty. Zohar, how'd you get into this crazy, wacky world of application security? **2:48 Zohar Shachar:** So, my, my origin, well, I started at the IDF here in Israel. We have mandatory service in the IDF. So, when I was 18, I joined the H200 unit, which is the sort of Israeli equivalent of the NSA. No, it sounds like a highly classified thing, but at the end of the day, we just did a lot of technology. So, this is where I was introduced to, um, Basic stuff like writing code, SQL, Active Directory, managing large servers, mainframes. This was my introduction into technology. Spent the 3 years, and then after I got released from the army, did my studies. During my studies, I started my first job as a security consultant in a small company. I was very lucky to be one of the first consultants in the company. I think I was like the second or third employee there. Uh, which meant that I was, uh, able to, to be involved in a lot of projects very early on and move fast and do a lot of interesting things and research a lot of interesting topics. So anything from, well, started application security, like the basic pen test you would expect, and pretty fast we moved to red teaming and infrastructure penetration testing, a lot of stuff. Spent there around Seven, eight years almost. Throughout the time, I was also managing some AppSec teams and ended up as the CTO there. And after these seven and a half, eight years, I decided to quit, and at which point I was like searching for my next challenge. Had a phone call to a colleague, Chen Guo Ye, which you had here on the show. A few episodes back, he was at the time working for Wix, and I was chatting with him because I was kind of wondering what should be my next step, and he was from a similar background. So I wanted to hear how it's going for him at Wix, and he was very warm about it and suggested that I join the team. Little did I know that two months after I joined my team, joined the team, Ken, along with the who was there, the team leader, and another senior member of the team all left together to form their startup, Enso Security. And the team was left without a team leader. And for reasons unknown to me, the CISO at the time decided to come to me and ask me to take over the team, even though I was very new to the company and to the team. **5:24** Mm-hmm. **5:26 Zohar Shachar:** But ever since then, it's going great. I'm at Wix for the last 3 3 years and the team became a group. And now we are like 13 OPSEC professionals and it's— **5:38 Chris Romeo:** Nice. **5:38 Zohar Shachar:** Going great. Yeah, it's been a blast. And here we are. **5:42 Chris Romeo:** Yeah. So I do have a question for you in regards to, so you said you spent some time as a breaker, right? So some number of those years you were breaking stuff, right? Yeah, yeah. **5:53 Zohar Shachar:** Most of the time. **5:54 Chris Romeo:** So what was, I always love to hear people's stories about the silliest thing or like what was the thing that you what you broke and it was like the easiest thing and it shouldn't have been? **6:05 Zohar Shachar:** Oh, well, you know, there were a lot of things, but one of the stupidest things, we were doing some red team with a Fortune 500 company and we were trying to target like 5 or 6 different data centers across the world from the internet, trying to find a way in. And we knew we had the targets, like we wanted to gain control of the subsystem. And with one of those data centers, we had basically nothing. We couldn't find any application vulnerability, any network vulnerability, nothing. But we did find the login to the subsystem. And after a few weeks of trying everything we had, we were like, hmm, maybe let's just try the default credentials, which should be the first thing you do, right? But we didn't. And then we're just like, yeah, sap*. Password admin/admin. And we were in and just like— **6:59 Chris Romeo:** Wow. **7:00 Zohar Shachar:** Game over. And it was both funny and frustrating spending so much time trying to find a real vulnerability and ending up with this stupid default credential. **7:12 Chris Romeo:** There is a lesson learned there, right? Like, and we know it from the world of attackers, attackers always take the least path of resistance. **7:21** Yes. **7:22 Chris Romeo:** Like, everybody always imagines it's like on TV and the movies, and they did 17 steps and they jumped out of a helicopter and then they somehow managed to bypass the access control. Uh-uh, not how it happens in reality. Reality, they're like, admin, admin, done. Oh yeah, we're in. Like— **7:37 Zohar Shachar:** Yes, unfortunately that's true. It's always far more interesting and fun to find something real and technically complex and everything, but at the end of the day, yeah, simple social engineering usually does the work for you, yeah. **7:56 Chris Romeo:** So you mentioned, I know you spoke at OWASP Dublin. So tell us about, there's something that I think you mentioned, don't let bug bounty kill your application security posture. What does that mean? **8:13 Zohar Shachar:** Yeah, I know it sounds kind of controversial. So I think it's worth saying from the beginning, I actually love bug bounty. Like, I did a lot of bug bounty myself. I have a lot of experience with the offensive side of bug bounty. My main target over the years was Google because it's like, for me, it sounded like the most interesting challenge and the most difficult one at the time. So I spent a lot of time doing bug bounty, but since I joined Wix and since I started managing a bug bounty program, I realized there's another side to this tale. Yeah. Sometimes the researchers don't see the full picture, or even usually they don't see the full picture, and they focus on stuff that are, again, interesting to the researcher, maybe lucrative to the researcher from financial perspective, but are not necessarily the thing that the organization needs to focus on. And from conversation I had both within Wix and later with colleagues from other organizations, became clear to me that many teams, many AppSec teams give a lot of attention to bug bounty as their almost main source of information regarding their posture. And they tend to look at bug bounty as a measurement, like, how am I doing? Let's look at what comes from bug bounty. Let's look at the researcher pool and see what they can tell us. And unfortunately, I find that it's not a real reflection of your posture. It's a skewed view. We can go into details. I'm sure we will in a moment. But generally, I just think that this is like the biggest problem, right? Getting a perspective that is only one perspective and it's partial, but turning it into the full picture is a danger that you should avoid if you run a program. **10:09 Chris Romeo:** So let's kind of go back in the Wayback Machine here for a second. Give us some perspective on your experience as a bug bounty hunter. I know you said you participated in some of these programs, and so give us some perspective on what you've accomplished as a hunter in the bug bounty world. **10:32 Zohar Shachar:** Yeah, so my first steps were probably 4 or 5, 6 years ago. I think bug bounty was pretty fresh then, and I remember having a conversation with a colleague who was like, Oh, there is good money there. We should probably get involved with some bug bounty after work. And at the time, there was some blog post saying that, well, you know, there's a lot of hype of the bug bounty and a lot of money there, but actually someone did some research and found that the top bug bounty researchers at HackerOne make like $50K a year, something of the sort, which was at the time, it sounded like a bit, Not the goldmine that people thought it would be, but still it got us interested, right? So we started poking around first with some, I don't know, the first programs we saw on HackerOne and the first bugs I reported were really stupid just to get my toe in the water. I actually referenced this in my talk in Dublin. One of the first bugs I reported was Not a bug. It's kind of embarrassing to admit that I even reported it, but it was some redirect loop. As stupid as it sounds, like you can direct a user to an endpoint and it goes into a loop of redirects and the browser tells you, okay, I can't load the site, which of course has no security implication whatsoever. But I, you know, I was trying to figure it out, so I reported it and surprise, surprise, I was paid. Not a lot, but still, you know, some money, $100, I think, something like this, which got me more curious. But pretty quickly, I moved away from these programs of companies that I didn't even hear of to focus on what was for me the big fish, which was mainly Google. Yeah, I spent, I think, around a year and a half, 2 years in which I was pretty focused on this. So after work, I was still a full-time employee at the time, but after work I would spend, I don't know, something between 2 and 5 hours depending on the day, sometimes over the weekend, a lot of research around discovery of attack surface, trying to develop new attack techniques that I thought would work with Google. Ended up finding some interesting stuff. Like there were a lot of cross-site scripting and stuff that were not that interesting, but also some SMTP injections or SSDIs or things you would think that are not that— you wouldn't expect to find them with Google, but if you try, you might succeed, right? And I was there around the time when they also started their Well, Google have few programs, but they have something that they started like a few years ago called the Abuse Program, which is bugs that are more logic bugs and not really software bugs that you can exploit to sort of a system that works as intended, but still have some vulnerability in the logic. So I was one of the first there, which I had good connection with the person who was running the program then. Ended up being one of the top contributors at the time. They referenced me in some posts. It was fun. I reached number 20, 24, I think, in the Hall of Fame. Went to some conferences and stuff. But then I just stopped. I don't know, like one day just stopped. Moved on to other things. Lost my energy. **14:19 Chris Romeo:** So, on the side of the researcher then, because I've heard other people, I've seen other stories about how much people actually make as bug bounty researchers, the people that aren't maybe at the top of the leaderboard. And so, when you think about like the amount of time you put in, did you get paid enough money to make it worth the amount of time you put in or were you effectively working for minimum wage by the time it was all kind of tallied up? **14:53 Zohar Shachar:** So it's hard to say, 'cause for the first few months I found nothing, you know, researching Google. **15:00 Chris Romeo:** Yeah. **15:00 Zohar Shachar:** I spent a lot of time finding nothing. It took me a long time to figure out the tech behind it and research some protocols that I was not too familiar with. But once I sort of managed to find my way through the madness. It became pretty, pretty like good money. Like I could spend a day or two to make whatever, $5K. **15:26 Chris Romeo:** Okay. **15:28 Zohar Shachar:** Over the course of time, I made some good money there. And I would also say that I met some of the top, top researchers of Google. Again, it was a few years ago, but at the time they were making half a million dollars a year or something like this. So the people at the top make a lot of money, certainly. Yeah. **15:50 Chris Romeo:** So going back in history a little bit, what was the bug bounty supposed to be when it started? **15:59 Zohar Shachar:** Well, that's a good question. And I will say that this is my perspective or how I understand things. Some people might argue, of course, but to me and how I understand it and talking to people way back then, bug bounty was meant to be a way for you as a researcher to reach out to an organization and say, hey, you have a problem. Like, I found something, I discovered some problem. Who do I even report this to? It's not about money. It wasn't, sorry, about money. It was about making the web, you know, more secure, as, you know, naive and, uh, uh, I don't know, utopian as it sounds, right? Uh, and, you know, I, I did some of it myself. I reported some vulnerabilities to some companies many times, uh, through different channels, you know, just finding some email of someone or finding someone on LinkedIn and, you know, hey, I found a SQL injection here, there, I find some issue there. You better fix it. Don't pay me. I'm not asking for money. I'm not robbing you or anything. Just, you better fix it, right? So I think that was the original intention. Because unfortunately, Steve, you— it's not that uncommon to find issues and have no one to report them to. So you need to have this channel. You need to have a way to communicate with the security team on the other side. And I think giving a bounty for it is just originally the way for the company to say thank you. And it used to be something small like a t-shirt or, you know, like swag or free, I don't know, free admission to the conference or something, you know. But it became something like almost hiring the professionals in a different channel. Instead of hiring someone for real, you pay a lot for bounties and you say, okay, research me, show me what you've got. **17:57 Chris Romeo:** So when you think about bug bounty versus pen testing, as since you're, you mean you're somebody who's done both. So you have a far too often people try to, would try to answer this question who've only done one or neither. And, but given that you've done both bug bounty and red teaming slash pen testing, How do you compare and contrast those 2 disciplines? Are they the same? Are they completely different? Like, what are your thoughts there? **18:29 Zohar Shachar:** I think they're completely different. I would even say the skill set is different. And let me explain. When you do penetration testing, first of all, you are expected to have some coverage of the application you're researching. Expected to look at everything and anything that might have some security implication. So, you know, you need to test the application, let's say, for cross-site scripting, for SQL injection, for authorization bypass, and for user enumeration, and for, I don't know, weak password policy, and for weak headers. I don't know, like everything and anything, because you're supposed to be the person to tell the company what they need to do to fix the problem. You need to have a wide picture, um, and you need to put it in a report and you need to explain it properly and you need to understand the risks behind the issue you're finding. So you need to prioritize what is more important, what is more risky, what's the probability of some issue being exploited by someone else. You need to do the entire AppSec process from discovery to exploitation to understanding of the implication and, and, and probably also discuss the fix and help the company understand how they should address the issue you found. So you need to have, in my mind, a deep understanding of the technology you're dealing with and the application you're researching. And the skill set is quite substantial. However, when you do bug bounty, at least on most cases, you are not expected to do any of that. You're expected, if you find something, let us know, right? So you're not meant to do coverage. You don't mean to understand necessarily the implications of what you're doing. You can be, you know, the wizard of cross-site scripting. This is All you know, but you go from website to website to website to website and find cross-site scripting and report them. You don't even understand how it should be mitigated. And you don't know nothing about other attack vectors because this is not your trade. You are a cross-site scripting wizard. And this is— both are valuable skill sets, but they're different and they provide different value for the person on the other side. So I don't think one can replace the other. They complement each other, but they're not equal. **21:00 Chris Romeo:** So, here's the million-dollar question. If you could only do one, what would it be and why? **21:11 Zohar Shachar:** If you can only do one, you're probably in trouble. **21:17 Chris Romeo:** That wasn't an option. Come on, this wasn't multiple choice. I agree, I agree. **21:25 Zohar Shachar:** Yeah, like only doing penetration testing is, is not worthwhile. Like it will not give you anything if you just do penetration testing once and you think that gave you some— like it's true for the time in which the test was done and a month later there are new features, new development, and everything is different. It's not, it's not enough. Uh, but bug bounty is also not enough, you know. It's, it gives you what it gives you. Like, you need to have a wide set of tools. Um, if I had to let one of these go in a wider scope of things, I think I would let penetration testing— I, I would keep penetration testing and let bug bounty go if I only had to choose one, because penetration testing, I know what I'm getting. Bug bounty, it's like a gamble. But, but don't do only one of those. **22:14 Chris Romeo:** Yeah, I guess with pen testing, you're getting To your point earlier, it's, you're getting a wider viewpoint that's checking 27 different potential things. Whereas bug bounty, I might be, like you said, you might have the cross-site scripting expert. And so all they're doing is looking for cross-site scripting. They could care less about account enumeration or broken access control or any of the other, anything else that a pen tester's gonna be wide, more widely looking at. Yeah. **22:45 Zohar Shachar:** Yeah, and you just also, you don't know, right? You have a bug bounty program, you have no idea what they look for. Like, what did they try and fail? I have no idea. Did they attempt something? I don't know. They don't tell me, you know, they only tell me what they succeed. **23:01 Chris Romeo:** Yeah. **23:02 Zohar Shachar:** And I don't, I have no idea how to estimate the coverage or the potential damage. what they found. **23:10 Chris Romeo:** Hmm. That feels like there's some danger here. Maybe that's what you're going to get into when we talk about how can bug bounty do harm. But it seems like there's some danger that you could have a false sense of security. **23:24 Zohar Shachar:** Yeah. **23:25 Chris Romeo:** If you're somebody who's using bug bounty and you're like, if you're not careful, you could really believe that the security properties of your system are much higher/better than they actually are because you could get into that, you could fall into that trap of, well, I mean, the bug bounty hasn't returned anything in the last couple months. And so hence, that means we're secure. Whereas I think those of us that have been around the block a few times would be like, no, that does not mean you're secure. That means nobody focused in the right areas to break your stuff. **24:01 Zohar Shachar:** Exactly, exactly. You know, like, it reminds me of, um, uh, some of the, uh, voices that were heard around, uh, COVID at the time, that, you know, if you stop testing for COVID, you don't find sick people, so you have no COVID. So why should you test? You know, uh, you don't test, you don't know. So it's the same thing, right? You don't do penetration tests, you don't find problems. By the way, you can also not have bug bounty and then you're perfectly secure. There are no problems whatsoever. Completely compromised by someone, right? But yes, I agree with you. **24:42 Chris Romeo:** Imagine if somebody invented a new service. It's lack of denial. I'm trying to think of what we would call this service. Yeah, we'll just basically tell you that everything's good and you can— it'll help you sleep at night. You know, it'll cost a lot of money though, because we're going to need a lot of liability protection given the fact that all we're doing is giving— it'll be a false— ah, okay, here's the name of the service. It's called A False Sense of Security. It's available for $9.99 from wherever you buy books or whatever these days. So, how about harm? What other areas? What other areas can, how can bug bounty do harm other than kind of the false sense of security? **25:26 Zohar Shachar:** Yeah, so the other side that I think is problematic is shifting your attention. And what I mean by that is, let's say you do have bug bounty program and they do find things, right? They report issues. Are those the issues that you need to deal with? Not necessarily. So for example, we have in our bug bounty program, a lot of reports around subdomain takeovers. This is a very common thing for almost every program. Why do we have a lot of these reports? Well, I know because I'm, you know, also a researcher that subdomain takeovers are very easy to automate. You don't need to have, You don't need to spend a lot of time to find them, and it's easy money. In a lot of cases, it's just easy money. You write a script, you go through targets, you find more and more and more subdomain takeovers, you report them, and, you know, they don't pay that much, but they pay some, and you multiply it by many findings and you make a nice bounty. So if you just use this as a reference to what your problems are, you, like, we might find ourselves dealing with subdomain takeovers, all the time. Like, we have a limited amount of resources we can invest in security. If we just focus on that, we will not do anything else. However, I, you know, from the side, not of the researcher, but of the AppSec expert within the company, I know that we have other issues that are far more dangerous that require our attention. **27:04 Chris Romeo:** Yeah. **27:05 Zohar Shachar:** So the risk, as I would put it, or the harm it can do you is changing your priorities according to what was found externally by bug bounty researchers instead of what you know internally as the application security professional. You need to keep your focus on the right places, not on where the researchers focus, 'cause their motivation is different than yours. **27:32 Chris Romeo:** So it sounds like it's a bit of, like I said, focus and attention. You know where the problem is, or you know what's inside the perimeter more than they do. And so if you let them drive it, then you can be focusing completely the wrong place. **27:50 Zohar Shachar:** Yeah, I mean, of course I don't know anything. And of course, once in a while there is a report that highlights something that I was unaware of, and these are the most valuable reports. But if you talk to some program managers, you will find that they have surprisingly the same issues, you know, each program, same issues. But it doesn't mean that the organizations have the same issues. It's just the researchers are doing the same things. Yeah. **28:24 Chris Romeo:** Yeah. What are some other tips that you can offer to help avoid a bug bounty causing issues for the AppSec posture of an organization? **28:35 Zohar Shachar:** So I think I would say the most important thing is just awareness. Just be aware of what you're getting and treat it with caution, right? There will be, or at least in my case, but I think it's common, there's a lot of pressure on the security team to address bug bounty and maybe prioritize the bug bounty and maybe measure according to bug bounty by people. The pressure comes from people who are not security professionals. They come from the, you know, R&D management or the, I don't know, sometimes the marketing team, sometimes other— **29:19 Chris Romeo:** Yeah. **29:20 Zohar Shachar:** bodies within the company that need to have some sense of measurement of security. Maybe they need to speak about it, and bug bounty is the easiest thing to look at. You need to push this pressure back and not let it shift your attention and focus. You need to just run your AppSec program according to the risk you identify and just use the bug bounty as the tool A very important tool, a very, I don't know, like even a key thing in the package of tools that you have, but just a tool. It's not the one thing to follow. So this is one thing, perspective. And the second I would say is also be aware of hiring bug bounty researchers. **30:12** Yeah. **30:14 Zohar Shachar:** Again, not saying not to hire them, but just be aware that when you hire a bug bounty researcher, a person who spends a lot of time doing bug bounty, they come with some predetermined set of methodologies that might not be applicable to what you need from an inside perspective. And this is also something that I, sort of found talking to colleagues that many, many of my colleagues face the same problem that, you know, they recruit someone who is a very good bug bounty researcher, meaning that they make a lot of money and find a lot of issues, but it doesn't necessarily mean that they are very good AppSec professionals. And sometimes teams start internally becoming like bug bounty teams instead of So this is also something you need to be aware of, again, like direct your team also in the right places and be aware of this potential drift towards bug bounty. I think it's also good to challenge your researchers from time to time, the bug bounty researchers. We had some nice experiments at Wix, by the way. I also referenced this in my talk in OWASP. We tried to understand, like, how come researchers don't report SQL injection issues to us at all? Like, zero. We had no reports over several years. But, you know, you might draw the conclusion from this that we have no SQL injection vulnerabilities. But I think at this point of our conversation, we all understand that this is probably not the case, especially as internally we were aware of some SQL injection problems. So we tried an experiment and we reached out to our researchers and we say, hey, you know what, we're having a challenge this month and we're going to pay more for SQL injections, like 150% or something. The point of this challenge was to sort of tell our researchers, hey, look, we know you never reported SQL injections to us, but we are aware that we have some. Maybe it's good money for you to focus on that for a while. And it worked like magic, right? Like, we told them this is the challenge, and after 3 years of no SQL injection issues whatsoever, within the first week we got like 3 valid reports. So, what you can learn from this, or what we learned from this at least, is that our researchers are definitely capable, but they need the right motivation and they need to be pointed in the right direction. And we can't expect them to, uh, on their own decide to drift into new areas where they can, uh, discover new issues. We need to sort of let them know where we want to focus, um, and this might help, you know. So yeah, another tip there. **33:09 Chris Romeo:** Yeah, that sounds similar to what you said earlier, that the differences between a pen test or a penetration tester and how they look at the system versus a bug bounty being very direct, very specific about what they look for related to your request or what they know, what they're an expert in. Very interesting. **33:36 Zohar Shachar:** You can be very creative and you can do, you know, 150% for a new vulnerability class that we never had report on before, something of the sort, right? Just use all your imagination to motivate your researchers to go into directions that interest you. Yeah. **33:57 Chris Romeo:** That almost seems like a key takeaway, but I'll ask anyway. Do you have, are there any other key takeaways or specifically maybe a call to action, something you want the audience to do as a result of our conversation about bug bounties and how it fits in with AppSec? **34:15 Zohar Shachar:** I would love it if the industry would stop asking this question, can bug bounty replace penetration testing, and start asking how bug bounty can be used wisely to support penetration testing. The methodology should be discussed, I think, in a broader sense, how bug bounty supports the program and how to manage it properly. And to be fair, we get a lot of support, like, I didn't mention it, but we run our bug bounty program through HackerOne, and we get support from them and a lot of suggestions on how to direct the program better. I think it can be discussed in wider environments between the organizations. It's something that I started doing with my colleagues, but, you know, if there can be some broader discussion, I think it would be valuable so everybody can value from it better. It will also tell the researchers how, um, how to make their work more impactful, which is, um, also important for the researchers to know, right? This is how you make a change. So yeah, I'd be happy if some conversation like this started. Maybe this podcast will start it. **35:28 Chris Romeo:** Yeah, maybe folks can reach out to you directly to, uh, continue this conversation and, and if they want to contribute and, uh, We'll put links in the show notes to how they can find you to pick up and continue this conversation. So, Zohar, thank you so much for joining the show and for sharing your perspectives here on bug bounty and AppSec posture and, you know, how these things kind of interrelate. Certainly enlightening for me as well. Just getting your take on the difference between bug bounty and pen testing was very— it was a good summary of that. I've never heard anybody really summarize that for me in the depth that you took it to there. So that was really great. So once again, thanks for taking the time to be a part of the show, and we look forward to catching up with you again soon at another security conference. **36:21 Zohar Shachar:** Sure, sure. Thank you for having me. It's been a blast. Hope to see you soon. --- Source: https://appsecpodcast.com/zohar-shachar-bug-bounty-from-both-sides/