Microsoft Announces Windows Bug Bounty Program and Extension of Hyper-V Bounty...

 
 
 
Microsoft Announces Windows Bug Bounty Program and Extension of Hyper-V Bounty...

 
xda-developers
Jul 27, 2017 9:12 AM • by Steven Zimmerman
Microsoft Announces Windows Bug Bounty Program and Extension of Hyper-V Bounty Program

The Microsoft Security Response Center Team (MSRC) announced today that they will be launching a new targeted Windows Bug Bounty program (aptly named the "Windows Bounty Program"), in the hopes of catching vulnerabilities before they can reach the black market. The addition of a Windows Bug Bounty program comes as part of a comprehensive effort by Microsoft to improve their responsiveness and defences against security vulnerabilities.

This new Windows Bug Bounty program will go a long way towards helping identify and patch vulnerabilities in Microsoft's products, with a focus on remote code execution, privilege escalation, and inherent design flaws.

While users will be limited in their ability to submit patches for the issues found in the Windows bug bounty program as Windows is closed source (which can bring inherent security issues), just having the bug reports themselves will benefit Microsoft substantially with improving the security of their products, as Microsoft will be able to utilize the reports to investigate and patch the issues themselves once they are notified of the issues' existence.

Microsoft is also remodeling their Hyper-V Bounty Program to substantially increase their maximum payouts, in order to better compete with the prices found for those vulnerabilities on the black market, and to more appropriately compensate developers for finding issues. The new programs will have a maximum payout of $250,000 for a Hyper-V exploit with Remote Code Execution, and a maximum of $200,000 for Windows 10 exploits that are "Novel & fundamental advancement[s] in exploitation technology that universally bypasses current mitigations".

In addition to the payouts for the first person to discover the bugs, Microsoft is also offering to pay out that's 10% of the corresponding reward to the first person to report any bugs that are discovered internally but have not been published yet. While not quite the same as the full payout, receiving a partial payout for reporting a vulnerability after Microsoft has already discovered it will help encourage people to report vulnerabilities, as it will alleviate some of the disappointment that usually comes with being told that the bug that you have reported was already discovered.

With this move to expand the scope of their bug bounties, Microsoft joins a long list of companies that have remodelled their bug bounty system in the past year, including Google, Apple, Qualcomm, the United States Air Force, and many others.

It is no coincidence that the list of companies expanding their bug bounty programs is long and growing. Providing rewards for people who report bugs goes a long way towards encouraging people to report them to the company so that they can be fixed, instead of attempting to sell them on the black market. It gives a legitimate route for white hat hackers to make money from analysing your software, helping attract them to your ecosystem and maintain their interest. While it can be difficult to fully compete with the prices that certain exceptional vulnerabilities can go for on the black market, many hackers would much rather deal with legal methods of vulnerability reporting, and every vulnerability you can find and fix helps prevent said vulnerabilities from being used for unsavoury practices that can harm your users.

While bug bounty programs have been around for a long time and have consistently proven their worth, there has been a renewed focus on them as of late due to certain extensive security vulnerabilities that have been recently revealed, including the leaked United States Central Intelligence Agency's Vault 7, which contained security exploits for Microsoft Edge, Google Chrome, Mozilla Firefox, Opera, iOS, Android, macOS, Linux, and Microsoft Windows, among other targets. Microsoft in particular was heavily affected by security vulnerabilities last year, when it was revealed that the 2012 hacking of LinkedIn (which Microsoft bought last year) was substantially more widespread than had been initially estimated.

If you wish to report a security bug for Microsoft's bug bounty program, you can email them at  secure@microsoft.com following their Coordinated Vulnerability Disclosure (CVD) policy. If you have any questions about the program itself, the latest information about Microsoft's bug bounty programs can be found at https://aka.ms/BugBounty. The Windows Bounty Program is expected to continue indefinitely, although it will likely be tweaked as time goes on to fit the changing security landscape.


Press Release




Android Advices
Jul 22, 2017 1:59 PM • by Karthik Iyer
How To Install Android Nougat Based 5.8.3 Resurrection Remix ROM On Lenovo K6 Power Smartphone

Lenovo launched the new K6 Power smartphone a couple of months back and it is one of the most popular devices that Lenovo launched in recent times. It is a budget mid-ranged offering from the company which packs a huge battery and hence the name Power. It will easily last you for upto 2 days with medium usage on a single charge. However, if you own this smartphone, then you already know that the software on it is not the best one out there.

However, there is not a lot that you can do, other than flashing a third party custom ROM. There are a ton of options available for that in the market. Well, if you are wondering how to do it, then you are in the right place. Today we will show you exactly How To Install Android Nougat Based 5.8.3 Resurrection Remix ROM On Lenovo K6 Power Smartphone.

About the ROM

Below are some of the working features of the smartphone on this ROM –

  • Camera rear/front (Photographs)
  • Camera rear/front (Video – Use Camu from Play Store)
  • Auto brightness.
  • Fingerprint.
  • Bluetooth, Mic, Wi-Fi, GPS, IR
  • Hotspot
  • RIL

Now that it is out of the way, let's check out some of the requirements that are necessary for the installation. Below are some of the pre-requisite for the same –

Pre-requisite

  • The first thing which you need to make sure is that you are creating a complete backup of your files. Since we will be completely wiping the internal memory of the phone, you will end up loosing all your files.
  • You also need to make sure that you are installing a custom recovery software. You can install any of your choices, however, we suggest you go for TWRP for this installation.
  • You also need to make sure that the battery in the tablet has about 60-percent charge before you begin the installation. If your smartphone's battery dies during the installation, then you may end up with a completely bricked smartphone.
  • And lastly it is also necessary to make sure that you have downloaded the firmware file which is necessary for the installation. Without this file, you won't be able to proceed with the installation and hence we suggest you download the same from the link given below.

Download Resurrection Remix Nougat ROM For Lenovo K6 Power

Installation

  1. Assuming that you have downloaded the files given in the link above, it is now time to begin the installation process.
  2. The first thing which you need to make sure is that you copy the downloaded file to the smartphone.
  3. Once done, simply turn off your phone and enter into the recovery mode. You can do this by pressing Volume Down + Power Key at the same time.
  4. After this, once you are in the recovery menu, look for wipe and format option ⇒ wipe data, system, cache and Dalvik cache and initiate it.
  5. Once done, now return back to the recovery menu and tap on Install.
  6. Now it will ask you to browse for the firmware file which you had copied earlier. Simply navigate to the same and select it.
  7. After that simply swipe to begin the installation.
  8. Do make a note that the installation will take some time and hence we suggest you be patient with the same.
  9. After it is done, before rebooting you can also choose to install the GApps.
  10. Once this is done, your device will automatically reboot into the new ROM.

Do make a note that the first reboot may take a long time and hence we suggest you stay patient with the same. Having said, if you have any queries regarding the setup, then be sure to let us know by commenting down below and also stay tuned to Android Advices for more tutorials like this.




 
 

This email has been sent by Froze ONE (isnanmm0@gmail.com). It is the potion result of 'Tech: Topic watch' from the dashboard 'Personal Dashboard', tab 'Tech > Android'. Turn off or edit this potion

 

© Netvibes 2005-2017 | Terms of service | Privacy Policy

 
 

Subscribe to receive free email updates:

0 Response to "Microsoft Announces Windows Bug Bounty Program and Extension of Hyper-V Bounty..."

Post a Comment