Standoff | Bug Bounty 🌍
Статистика- Последний пост
- 13 авг.
- Последнее чтение
- 15 авг.
- Постов за неделю
- 1
- Всего постов
- 23
- Тип
- открытый
- Язык
- und
- В каталоге с
- 13 авг.
- 1/24сутки в ленте
- 25
- 1/48двое суток
- 28
- 1/72трое суток
- 30
Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.
Посты
Getting Started with Bug Bounty: Recon 🔎 How do you find what others miss? It starts with recon. In the new episode, we break down one of the key stages of bug hunting: how to explore infrastructure and discover potential entry points. Hosted by Oleg Ulanov aka brain, Standoff Bug Bounty Ambassador and one of the platform’s top security researchers. Our guest is Hussein Daher aka hussein98d, one of the top researchers on Standoff Bug Bounty. Inside the episode: subdomain and host discovery, network and ASN analysis, wordlist building, dorking, hidden parameter discovery, favicon recon, Reverse DNS, and real-world bug hunting cases. Watch the episode → Youtube
Cloudy, with a chance of vulnerability showers 💭 K2 Cloud just opened its bug bounty program to every researcher. You'll be hunting the critical high-impact bugs that put client infrastructure and data at risk 🗂 In scope: 🔗 RCE 🔗 Injections (SQL, XML, SSTI, and others) 🔗 LFI and RFI 🔗 SSRF with confirmed impact 🔗 IDOR and privilege escalation 🔗 Authentication and authorization flaws 🔗 Business logic and payment bypasses 🔗 Confidential data leaks 🔗 Anything else that breaks platform security Top reward, $6,520 💵 Think you can breach the cloud? Get started 🖱️
New bounties are now available on Standoff Bug Bounty 🆕 Positive Technologies refreshed its whole lineup of bug hunting programs. Here's what's live 👇 🪲 What changed: • Positive Dream Hunting has a new unacceptable event • Positive Bug Hunting has new terms • PT Cloud AF is unchanged 💡Here are the programs: • MaxPatrol EDR • MaxPatrol O2 • MaxPatrol SIEM • MaxPatrol VM • MaxPatrol 360 • PT Application Firewall • PT Application Inspector • PT Container Security • PT Data Security • PT Dephaze • PT ISIM • PT NAD • PT NGFW • PT Sandbox Email bugbounty@standoff365.com and we'll get you into the test environment. Go find the juiciest vulnerabilities on Standoff Bug Bounty 🖱️
T-Bank сyber evaluation program: a $655,738 reward pool 🤑 This is your chance to take on one of Russia's largest banks and test whether its infrastructure can withstand a real-world attack. Trigger a single non-tolerable event and earn up to $153,906. Here's how to participate: 🟡 Apply for the program. 🟡 Receive an invite and gain access to the cyber evaluation environment. 🟡 Trigger a non-tolerable event. The T-Bank сyber evaluation program takes place at Standoff Bug Bounty. Participate to earn exclusive achievements that will be added to your profile. A cyber evaluation is a red team–style bug bounty program. Instead of looking for isolated vulnerabilities, researchers focus on building a complete attack chain (kill chain) aligned with the program's objectives, such as obtaining administrative access to a system or demonstrating the ability to steal funds. Apply now before the window closes ⏳
BCS Bank is back on Standoff Bug Bounty 👍 The program is open to all bug hunters. If you've been eyeing a bank scope, now's a good time to jump in. Current payouts: ▶️ Critical, up to $3,350 ▶️ High, up to $1,610 ▶️ Medium, up to $670 ▶️ Low, up to $135 ▶️ Info, no reward Scope: 🔵 https://bcs-bank.ru/ 🔵 https://lk.bcs-bank.ru/ 🔵 *.bcs-bank.ru 🔵 Android and iOS apps (latest versions from bcs.ru) BCS Bank's attack surface is open for testing. Get hunting and get paid 💸
That's us at Hacks. Back home now 👍 The event's over, but the energy's sticking with us. Here's a little video from day two so you can get a taste of it—the buzz, the drive, and the community. See you at the next Hacks. New location, same electric vibe 🔛
видео или голосовое, без подписи
видео или голосовое, без подписи
видео или голосовое, без подписи
видео или голосовое, без подписи
Standoff Hacks Finals 🔥 Тор 3: 🥇 r0hack — MVP Standoff Hacks 🥈 freeman 🥉 BlackFan MVPs by program: 🏆 BlackFan — T-Bank 🏆 brain — VK 🏆 hussein98d — Jet Infosystems 🏆 Antart — Bitrix24 30 top bug hunters 350+ reports $300K+ in bounties Two weeks of high-intensity work: hundreds of submissions, rigorous triage, and real-world impact. Huge thanks to every researcher who kept the pace all the way to the finals. The next Standoff Hacks... coming soon 👀
Standoff Bug Bounty 2025 wrapped. Here's what the numbers say 🤔 We packed every payout, every vulnerability class, and every trend from the past year into a single report. The team combed through the platform and highlighted standout items, extending from researcher earnings, most common vulnerability types, all the way to where bug bounty is headed the rest of this year. We included tables and charts for clarity. What's inside: ➖ Who earned what and for which vulnerabilities ➖ The most critical flaws uncovered ➖ What's shifting in the bug bounty world in 2026 If you want to stay in the loop about how bug bounty is doing and what to pay attention to, check out the research in the link.
Kontur double payouts are live 🤑 From March 2 through March 31, qualifying bugs come with double payouts. This round targets the authentication system and account portal. Rewards for eligible vulnerabilities can reach $25,285. In scope: auth.kontur.ru identity.kontur.ru cabinet.kontur.ru api.kontur.ru/cabinet-api/* api.kontur.ru/auth/* Good to know: 〰️ Higher payouts apply only to the listed scope 〰️ Limit automated scanning to 5 RPS 〰️ Be sure to add the X-BugBounty: {standoff_username} header to all requests Snag vulnerabilities while double rates are active 😼
✉️ New message for you: hh.ru goes public on Standoff Bug Bounty Your dream job just landed —bugs and bounties are already waiting for you on the career platform. The program was previously open to a select group of researchers, but now hh.ru is opening its doors to every bug hunter out there. Earn up to $6,414 for discovered vulnerabilities 💰 What's in scope: • hh.ru • api.hh.ru • dev.hh.ru • talantix.ru • setka.ru • api.setka.ru Everything's set for the hunt. The only thing missing? Your report. Jump into Standoff Bug Bounty and make the internet safer 🔥
What is Standoff Hacks and how do you get in? 🤔 We sat down with one of our researchers, Hackerx007, to find out what participating in Standoff Hacks means to him. Dive into the amazing world of Standoff Hacks and explore it with us! Read the interview, then join the contest for a chance to win an invite to a party abroad 😎 1⃣ What does participating in Standoff Hacks mean to you? A lot! It allows me to challenge myself and push my hacking mentality to the maximum level. It was my first LHE, so I didn't think I would win, but while hacking, I discovered a new part of my skills! Under pressure, you discover new skills that you didn't think you were capable of. So what does Standoff Hacks mean to me? It means confidence and challenge! Winning an LHE against 32 elite hackers showed me that under pressure we can do things we didn't think we could do. 2⃣ You have participated in Standoff Hacks before. What are the most vivid impressions you remember? The spirit, the community, and the management! When I met the other hackers, it felt like we'd known each other for a long time. Even though we were against each other, everyone was hoping the other would win! We had such a beautiful time together. And the program managers were with us — Elizaveta from T-Bank and Alexander from WB — giving their support. And you know what? We didn't even feel like they were the program owners. We were joking, having fun! And the support we got from the Positive Technologies team — Alex, Max, Masha — was amazing. Those moments and the time we spent, the laughs... it's unforgettable. 3⃣ What is most important to you at such events: victory, experience, money, or the community? Experience and community. As I said, I discovered things I didn't think I was able to do. I learned critical skills — working under pressure allows you to learn new things! Also the community — making new friends who think just like you. You know, all hackers around the world share the same way of thinking, and that makes the connection much easier. As I said, we felt like we'd known each other forever. We had a lot of fun! So making new friends and learning new things — that's what I'm looking forward to. 4⃣ How do you usually prepare for Standoff Hacks — or do you deliberately not prepare? I would love to take a break for a few days before the event, so I can recharge my energy and be ready to hack day and night! 5⃣ What is the most challenging part of Standoff Hacks: the lack of time or the competitive pressure? Neither! The most challenging thing is proving to yourself that you can do it. Anyone can win. I was challenging myself, because when I started, I didn't think I could win, but I was trying to prove to myself that I could do it! The time was enough for me, and working under pressure is beneficial — so the real challenge was proving to myself that I can and I will! 6⃣ What are you most looking forward to at Standoff Hacks in China: complex bugs, networking, or the atmosphere? I'm not greedy — all three of them! Finding critical bugs gives me confidence, making new friends and connections, and enjoying the time with other hackers! See you in China!
Standoff Hacks is almost here 🔛 Standoff Hacks is back, and it's right around the corner. If this is your first time, below is the rundown. It's a closed, live-hacking event where top researchers spend two weeks hacking their way through exclusive corporate environments 🎉 Here's what awaits: ➡️ Lots of bugs. ➡️ Outstanding rewards. ➡️ A wrap-up that'll be lit! Here's how the contest works: ➡️ International Standoff Hacks We'll share the venue soon. Watch this space. ➡️ 2 giveaway invitations That's right, real invitations up for grabs. ➡️ Tons of programs More programs means more chances to hack and more chances to win invitations. Remember the rules: 🔴Spend two weeks hunting bugs, submit your reports, rack up points, and boost your chances of getting into Standoff Hacks. Dates 🗓 February 20, 10:00 AM to March 6, 11:59 PM (MSK) What do you need to do? ➡️ Uncover bugs in the OZON program. The more valid vulnerabilities you find, the better your chances of landing an invite to the premier private live-hacking event of the year. Go hunt! 🐞
New cyber testing program from Jet Infosystems ❤️ You can now test one of the most complex enterprise infrastructures out there, and see how it holds up under pressure ❤️ Key scenarios include: 🔵 Infrastructure control Domain administrator rights Virtualization access Server and backup management control 🔵 Protected privileged access perimeter access Isolation bypass Perimeter movement Protected perimeter network control What you need to know is: ➖OSINT and social engineering are allowed. ➖Phishing emails to @jet.su are permitted. ➖ Only non-destructive methods are allowed. ➖ Clients and partners are out of scope. Do not target their systems. ❤️ Earn as much as $19,588 in rewards Reward opportunities are available now, so jump in while the testing scope is still open. If you find a vulnerability, submit the report through the main bug bounty program ❤️
43 ruble millionaire bug hunters on the Standoff Bug Bounty platform 🤵 Intrigued? Let's recap Standoff Bug Bounty's performance in 2025. 📈 Last year, the platform saw growth across every metric: 🔘 233 programs launched — that's 2.2x more than the previous year. The bug bounty market is expanding rapidly; we are seeing increased participation not just from online services, but also from offline businesses, IT vendors, and government organizations. 🔘 Hackers submitted 7,870 reports, with 2,909 were accepted — a 34% increase year-over-year. As usual, the financial sector drove the most activity. 🔘 2025 shattered other records as well: ➡️ The highest single payout was $65,000, and the average reward rose by 12%, reaching $860. 🔘 Access control remains the top priority. In 2025, 58% of high and critical severity vulnerabilities fell into this category. It remains the most persistent issue in the platform's history. 🔘 Total payouts reached $2,110,435 — a 49% increase over 2024. However, our biggest achievement isn't the data — it's you, the community. Thank you for your contributions!
Flowwow is open to all bug hunters 🌸 Want to check how secure the flower and gift marketplace is? You're in the right place: the Flowwow platform can now be tested by all researchers! What's in scope: 🟢 Main domain: flowwow.com APIs and subdomains: apis.flowwow.com, envio.flowwow.com, api2.flowwow.com, api-shop.flowwow.com, api-email.flowwow.com, clientweb.flowwow.com 🟢 Mobile apps for iOS and Android: Flowwow, Flowwow Seller, Flowwow for Couriers, Hoog (ERP system) Join the program to make Flowwow even safer 🔒
Happy New Year! 🎄 This year was full of solid finds, strong reports, and well-earned bounties. Thank you for every vulnerability uncovered, every late-night test, and every program you helped make more secure. In the new year, we wish you compelling scopes, fair triage, and bounties that truly make you smile. And of course, warm holidays with loved ones, cozy evenings, and plenty of tangerines. Thank you for being part of our bug bounty community. See you in 2026 with fresh energy, new opportunities, and even more great reports ✨