The online file storage, synchronization and sharing service , Dropbox, was found to have 264 vulnerabilities, which were discovered by 45 hackers
It will take about $319,300 to cover security issues and secure Dropbox's huge number of users.
The disclosure was made as part of the regular bug bounty program, to which Dropbox, Inc. attaches great importance, since security is a key component.
ZDNet focused on one of the younger hackers, Jack Cable. Cable is 19 years old and has been working for HackerOne since he was 16. He has participated in more than 100 events and has identified 250 vulnerabilities. Cable believes that the “maturity” of the systems being targeted is crucial and that vulnerabilities always exist. According to him, when you look, you always find something. The issue is how companies handle the issue, once the vulnerability is found.
Dropbox's systems are "mature" (they've been running the Hacker One program since 2015), so more effort is needed to identify vulnerabilities.
The rewards are defined as follows:
- Remote code execution (RCE) on servers – $32,768
- Major identity theft – $17,576
- For counterfeiting issues- $13824
- Cross-site scripting on dropbox.com (in all browsers) – $12167
The HackerOne platform has been doing a fantastic job with bug bounty programs since 2012. It has 390,000 hackers and has organized over 1,300 bug bounty programs. The platform takes care of the discovery of errors with the aim of protecting and securing systems, applications, services and the Internet in general.
