Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security Management

1/11/2019
07:00 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now
50%
50%

Hyatt Hotels Kicks Off Bug Bounty Program

Hyatt Hotels is teaming with HackerOne on a new bug bounty hunting program that looks to pay up to $4,000 for 'critical' vulnerabilities in software.

Hyatt Hotels is looking to get into the bug bounty hunting game, with offers up to $4,000 to identify "critical" flaws in the software and applications that the company uses.

HackerOne, which has developed bug hunting platforms for client, will work with Hyatt to collect the vulnerabilities and pay out the rewards. Targets for this particular program include the main Hyatt website, hyatt.com, as well as m.hyatt.com, world.hyatt.com and the Hyatt mobile applications on both iOS and Android.

The program includes the $4,000 payout for critical vulnerabilities, as well as $1,200 for those deemed "high," $600 for "medium" and $300 for "low." The degree of the flaws is based on the Common Vulnerability Scoring Standard (CVSS).

The types of vulnerabilities and flaws that Hyatt and HackerOne are looking for, include: Novel origin IP address discovery, authentication bypass, back-end system access via front-end systems, business logic bypass resulting in financial gain to an attacker (e.g., forced rate change), container escape, discovery of Hyatt data on public cloud storage services, novel means of automating account checking or rate scraping (e.g., botting), publicly available cloud systems that may host Hyatt information, SQL injection, cross-site request forgery, exploitable cross-site scripting, and WAF bypass.

As this is ethical hacking, the bug bounty guidelines clearly state a list of "do nots" for those participating, including accessing customer data or credit card numbers, destroying data or posting data and sensitive information on public forums, such as GitHub.

This type of hacking operation in nearly the opposite of Zerodium, which pays a premium for undisclosed vulnerabilities that are then given to clients, including government agencies. (See Zerodium Ups Ante for Zero-Day Exploits, Especially in iOS.)

In a statement posted January 9, Hyatt executives claimed this is one of the first bug bounty programs implemented in the hospitality industry. It also comes as a time when rival hotel chain Marriott has come under scrutiny for a massive data breach affecting more than 300 million customer accounts, and included the theft of passport numbers and other personal data. (See Marriott Revises Data Breach Numbers as Investigation Continues .)

"At Hyatt, protecting guest and customer information is our top priority and launching this program represents an important step that furthers our goal of keeping our guests safe every day," Hyatt's CISO Benjamin Vaughn noted in a statement. "As one of the first global hospitality brands to launch this type of program, we extend the ways we care for our guests and deepen our commitment to protecting their sensitive information."

Hyatt manages more than 750 different hotels and other properties in 55 different countries.

In a question-and-answer interview posted with HackerOne, Vaughn noted that the bug bounty first started with a private, invitation-only event before going public. So far, $5,650 in payments have been issued and 14 different reports have been resolved.

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Cloud Security Threats for 2021
Or Azarzar, CTO & Co-Founder of Lightspin,  12/3/2020
Why Vulnerable Code Is Shipped Knowingly
Chris Eng, Chief Research Officer, Veracode,  11/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Assessing Cybersecurity Risk in Todays Enterprises
Assessing Cybersecurity Risk in Todays Enterprises
COVID-19 has created a new IT paradigm in the enterprise and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27772
PUBLISHED: 2020-12-04
A flaw was found in ImageMagick in coders/bmp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned int`. This would most likely lead to an impact to application availability, but could po...
CVE-2020-27773
PUBLISHED: 2020-12-04
A flaw was found in ImageMagick in MagickCore/gem-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned char` or division by zero. This would most likely lead to an impact to appli...
CVE-2020-28950
PUBLISHED: 2020-12-04
The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process.
CVE-2020-27774
PUBLISHED: 2020-12-04
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of a too large shift for 64-bit type `ssize_t`. This would most likely lead to an impact to application availability, but co...
CVE-2020-27775
PUBLISHED: 2020-12-04
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned char. This would most likely lead to an impact to application availability, but c...