Hostilla.pl IT glossary
What is bug bounty?
A bug bounty is a program for reporting vulnerabilities in exchange for a reward or recognition. If a client runs such a program for their hosted application, they should clearly define the scope of testing. Tests cannot cover Hostilla infrastructure without consent and agreed scope.
Definition
A bug bounty is a program for reporting vulnerabilities in exchange for a reward or recognition. If a client runs such a program for their hosted application, they should clearly define the scope of testing. Tests cannot cover Hostilla infrastructure without consent and agreed scope.
What does it mean in practice?
For hosted services, bug bounty matters when identifying threats, limiting access, preserving evidence and verifying that a remediation really worked.
A practical Hostilla.pl example
For a security incident, record the affected account, domain, source IP and timestamp before changing logs or files. bug bounty is useful only when it is connected to evidence and a controlled remediation step.
What should you check?
- the affected service, URL, account and time window
- server, application, authentication and mail logs
- known-good backups and the last controlled change
- least-privilege access, containment and a verification test