United Airlines is offering a reward to researchers who can find vulnerabilities in any of the company's websites, programs or applications as part of its new bug bounty. The program has excluded security vulnerabilities related to aircraft internal flight systems, which the US government says are frequently targeted by hackers.
The bug bounty program announced by the company does not reward researchers with cash, but with “award miles” that can be used for the company’s Mileage Plus customer loyalty and rewards program.
Many companies have launched similar reward programs for finding vulnerabilities, in order to attract independent researchers to examine their software code and confidentially report vulnerabilities before they are discovered by hackers.
H United may be the first airline to launch such a program, but according to the official announcement, it will not accept reports of bugs that have been found in the internal Wi‑Fi network, in the entertainment systems or in the aircraft's electronic systems.
The company even warns of possible criminal and legal investigation for any attempt to check the live systems of the airplanes or the aircraft systems by third parties, for the purpose of identifying vulnerabilities.
The airline offers 1.000.000 “miles” for identifying remote code execution vulnerabilities, 250.000 miles for issues such as authentication bypass, brute force attacks or timing attacks, and 50.000 miles for cross-site scripting and request forgery vulnerabilities.

