Skip to Content
97 Things Every Application Security Professional Should Know
book

97 Things Every Application Security Professional Should Know

by Reet Kaur, Yabing Wang
June 2024
Intermediate to advanced
310 pages
8h 59m
English
O'Reilly Media, Inc.
Content preview from 97 Things Every Application Security Professional Should Know

Chapter 73. In Denial of Your Services

Allen West

The attack of disclosure to discourage further snooping is somewhat of a tradition now within the cybersecurity world. Old-timers in the vulnerability research world can tell you that the ecosystem of getting paid for responsible disclosure of findings used to be much riskier than it is today. Bug bounty was designed for that. Without formal bug bounty programs, let alone bug bounty hosting platforms like we have today, it was often a toss-up of how an organization would react to the disclosure of vulnerabilities in their systems. Many times, companies that were unsure how to handle situations like this would often resort to legal action against the researcher, which inevitably led to fear of disclosure and community backlash to the responding company. A lose-lose scenario.

Over time, most companies have come to appreciate the contributions that freelance vulnerability hunters provide and have tried to formalize the process, laying out clear guidelines of what they do and do not want researchers to try when testing their applications. Some common off-limit items include brute forcing, social engineering, purchase of compromised credentials on the dark web, and commercial vulnerability scanners, just to name a few. Basically, anything that would incentivize misbehavior or interrupt actual business.

Security decisions are often ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

97 Things Every Information Security Professional Should Know

97 Things Every Information Security Professional Should Know

Christina Morillo

Publisher Resources

ISBN: 9781098152161Errata Page