US Army website infiltrated by bug bounty hacker
The US Army has detailed the results of its first bug bounty programme, which invited security experts and hackers to find flaws in the military’s websites, networks, and databases.
The Hack The Army bounty was deemed a success, with over 400 bug reports submitted. 118 of these reports were unique and actionable, stated Threat Post.
“Participants who found and reported unique bugs that were fixed were paid upwards of $100,000,” stated the report.
371 people were invited to take part in the programme, 25 of whom were government employees.
Big vulnerability
One researcher discovered two vulnerabilities on the goarmy.com website – which in isolation were not considered high level.
When chained together, though, the user could “access, without authentication, an internal Department of Defense website”.
“They got there through an open proxy, meaning the routing wasn’t shut down the way it should have been, and the researcher, without even knowing it, was able to get to this internal network, because there was a vulnerability with the proxy and with the actual system,” stated a post published on HackerOne.
The vulnerabilities have since been addressed.