Threat Intelligence

12/12/2018
04:00 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Bug Hunting Paves Path to Infosec Careers

Ethical hackers use bug bounty programs to build the skills they need to become security professionals.

Current and future cybersecurity professionals are using bug bounty programs to gain skills they can use to become security analysts, CISOs, or, in some cases, full-time vulnerability hunters.

As part of its 2018 "Inside the Mind of a Hacker" report, researchers at Bugcrowd polled 65,000 hackers from around the world to better understand who they are, what motivates them, and the sustainability of a hacker career. Most (81%) respondents credit bug hunting with helping them land a job in the security field, and many continue to use it to supplement full-time roles.

Five to 10 years ago, there weren't enough bug bounty programs to turn the practice into a full-time position, says Jason Haddix, vice president of researcher growth at Bugcrowd. Now there is more opportunity: The top 50 hackers' average yearly payout is $145,000, with over 600 valid submissions. The average payout per bug across the platform is $783.

Still, more people prefer to bug hunt on the side while working other jobs or attending university. Students spend 10 to 20 hours per week on ethical hacking, Haddix explains, and 66% of all Bugcrowd respondents spend up to 10 hours per week bug hunting. The practice is giving them valuable skills they can use to help fill the growing security talent gap.

"One of the things that was cool about this report was the amount the hunters are using this experience – finding vulnerabilities and bug bounties – to find jobs in security," Haddix says. It's an interesting educational path in a field where traditional college programs struggle to keep up.

Nearly 41% of bug hunters teach themselves and 43% use blogs and online resources to learn the skills they need. It's a highly motivated group: Nearly 32% want to be full-time bug hunters, 15% aspire to be security engineers at major tech companies, and 6% are training to be CISOs.

The Best Education Is Experience
You don't need a lot of experience to get into ethical hacking, Haddix points out. While 41.5% of hackers polled have three or more years of professional security experience, close to 30% only have one to two years, and 14.3% have no security experience at all. Bugcrowd's hackers are relatively young, with nearly all (94%) between the ages of 18 to 44 and 71.5% between the ages of 18 and 29.

Higher education is still popular; 80% of respondents have attended college. But the percentage of those with a master's degree (18%) matches the percentage of those who have a high school education or less. "Formal education is becoming the road less traveled," Bugcrowd reports. Bug hunters have both the skills and experience companies look for in security job candidates.

"It's powerful to say, 'Instead of taking a certification or class, I found a critical vulnerability on a Fortune 500 company,'" Haddix explains. What's more, they can offer proof of their expertise with a bug disclosure or status on a leaderboard. It goes "leaps farther" than a certification, he says.

The most prominent skill bug hunters learn is Web application hacking, which Haddix says makes up the biggest portion of today's bug bounties. For those getting started, learning Web application testing is a good gateway into ethical hacking – and where the most opportunity is. Most university courses don't dig into Web hacking, he adds, and online resources provide wannabe hackers with fake vulnerable applications they can dig into for practice.

"Practical experience is the one thing you seem to lack in today's security researchers," Haddix adds. "We need people with experience. New people are having a hard time getting into security."

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Crowdsourced vs. Traditional Pen Testing
Alex Haynes, Chief Information Security Officer, CDL,  3/19/2019
BEC Scammer Pleads Guilty
Dark Reading Staff 3/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Cyber Security Incident Response
The State of Cyber Security Incident Response
Organizations are responding to new threats with new processes for detecting and mitigating them. Here's a look at how the discipline of incident response is evolving.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-10014
PUBLISHED: 2019-03-24
In DedeCMS 5.7SP2, member/resetpassword.php allows remote authenticated users to reset the passwords of arbitrary users via a modified id parameter, because the key parameter is not properly validated.
CVE-2019-10015
PUBLISHED: 2019-03-24
baigoStudio baigoSSO v3.0.1 allows remote attackers to execute arbitrary PHP code via the first form field of a configuration screen, because this code is written to the BG_SITE_NAME field in the opt_base.inc.php file.
CVE-2019-10017
PUBLISHED: 2019-03-24
CMS Made Simple 2.2.10 has XSS via the advanced_search.php Name field, which is reachable via an "Add a new Profile" action to the File Picker.
CVE-2019-10010
PUBLISHED: 2019-03-24
Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using double-encoded HTML entities that are not properly escaped during rendering, a different vulnerability than CVE-2018-20583.
CVE-2019-9978
PUBLISHED: 2019-03-24
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.