Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit fe49779

Browse files
committed
Merge branch 'master' of github.com:Hacker0x01/docs.hackerone.com
2 parents 517d76c + 6644bf4 commit fe49779

8 files changed

+23
-13
lines changed

.travis.yml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,13 +2,15 @@ language: node_js
22

33
node_js:
44
- "lts/*"
5+
- node
56

67
cache:
8+
yarn: true
79
directories:
810
- node_modules
911

1012
before_script:
11-
- npm install
13+
- yarn install
1214

1315
script:
14-
- npm run lint
16+
- yarn run lint

docs/changelog/2018/november.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -51,8 +51,8 @@ We now enable you to cancel disclosure requests. You can cancel your own request
5151
### Activities API Endpoint
5252
We added a new activities API endpoint that enables you to fetch all activities of your program incrementally by time. Learn more about the [activities endpoint](https://api.hackerone.com/#activities-query-activities).
5353

54-
### HackerOne VPN
55-
Hackers can now configure the [HackerOne VPN](/hackers/configure-the-hackerone-vpn.html) and access their VPN credentials for VPN enabled programs.
54+
### HackerOne Gateway (VPN)
55+
Hackers can now configure the [HackerOne Gateway (VPN)](/hackers/configure-the-hackerone-vpn.html) and access their Gateway (VPN) credentials for Gateway (VPN) enabled programs.
5656

5757
![VPN](./images/nov_2018_vpn.png)
5858

docs/hackers/hackerone-vpn-root-ca.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ path: "/hackers/hackerone-vpn-root-ca.html"
44
id: "hackers/hackerone-vpn-root-ca"
55
---
66

7-
In order to use the HackerOne VPN, you need to install the HackerOne VPN Root CA.
7+
In order to use the HackerOne Gateway, you need to install the HackerOne VPN Root CA.
88

99
Refer to these installation and configuration instructions for your platform:
1010

@@ -105,6 +105,6 @@ To install the HackerOne VPN Root CA to Firefox:
105105

106106
![Screenshot](./images/vpn-firefox-4.png)
107107

108-
The "Hackerone - Hacker VPN Service" certificate is now visible in your list of certificates.
108+
The "HackerOne - Hacker VPN Service" certificate is now visible in your list of certificates.
109109

110110
![Screenshot](./images/vpn-firefox-5.png)

docs/hackers/openvpn-clients.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ path: "/hackers/openvpn-clients.html"
44
id: "hackers/openvpn-clients"
55
---
66

7-
In order to use the HackerOne VPN, you need to install a VPN client that supports OpenVPN.
7+
In order to use the HackerOne Gateway, you need to install a VPN client that supports OpenVPN.
88

99
Refer to these installation and configuration instructions for your platform:
1010

@@ -15,7 +15,7 @@ Refer to these installation and configuration instructions for your platform:
1515

1616
To configure the OpenVPN client to your windows machine:
1717

18-
1. Download the OpenVPN **Windows Installer** from <a href="https://openvpn.net/community-downloads/" target="_blank">this page</a>.
18+
1. Download the OpenVPN **Windows Installer** from [this page](https://openvpn.net/community-downloads/).
1919

2020
2. Execute the OpenVPN Installer.
2121

docs/programs/hackerone-vpn.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,13 +6,13 @@ id: "programs/hackerone-vpn"
66

77
You can require finders to set up a virtual private network (VPN) instance with HackerOne Gateway (VPN) in order to find vulnerabilities in your program. The HackerOne Gateway (VPN) enables you to have granular control over finder activities on your program and assets.
88

9-
> Gateway (VPN) is available as an add-on. To learn more about adding HackerOne Gateway(VPN) to your program, contact your account manager.
9+
> Gateway (VPN) is available as an add-on. To learn more about adding HackerOne Gateway (VPN) to your program, contact your account manager.
1010
1111
![Gateway program UI](./images/gateway-1.png)
1212

1313
To manage your Gateway settings:
1414
1. Go to **Program Settings > Program > Hacker Management > Gateway**.
15-
2. Check to see if your Gateway is connected under the **Manage Global Gateway Access** section. You’ll see a green **Connected** icon to notify you that traffic is able to successfully flow through the HackerOne VPN instances. If traffic through the VPN is disrupted, you’ll see a grey **Disconnected** icon.
15+
2. Check to see if your Gateway is connected under the **Manage Global Gateway Access** section. You’ll see a green **Connected** icon to notify you that traffic is able to successfully flow through the HackerOne Gateway (VPN) instances. If traffic through the Gateway is disrupted, you’ll see a grey **Disconnected** icon.
1616
3. *(Optional)* Click **Disconnect Gateway** if you want to close your gateway to finders. Keep in mind that disconnecting your gateway will prevent finders from finding vulnerabilities on your Gateway-protected targets until you reconnect the gateway.
1717
<ul><li><b>Note:</b> If your Gateway is in full tunnel mode or if your assets are under a Content Delivery Network (CDN), you won't be able to disconnect your Gateway as disconnecting your Gateway will prevent hackers from hacking on other programs.</li></ul>
1818

docs/programs/pentest-faqs.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,6 @@ Can I incentivize pentesters to find vulnerabilities throughout the pentest proc
1111
Can pentesters test for apps that require specialization? | It depends on the specialization you’re looking for. We have pentesters with experience in web, mobile, API and external network/infra testing. As part of the pentest process, we ask customers to go through a scoping questionnaire to help inform our team on specific testing requirements.
1212
We want to avoid the possibility of finding a high number of vulnerabilities that could cause our bounty pool to balloon. What can we do to avoid that? | The HackerOne Pentest is set at a fixed cost. Given there are no bounties, and pentesters are compensated for their effort and time, the total cost is 100% fixed and predictable.
1313
Is retesting included? How much is it to add? | There is a 60-day window to initiate 2 retests per report at no additional cost. Retesting is handled by the pentest team to ensure accuracy and consistency.
14-
Are these pentests conducted by Hackerone staff or are they crowdsourced? | Pentesters are not HackerOne employees. Tests are conducted by our community. We have identified in our community those with existing professional pentesting experience.
14+
Are these pentests conducted by HackerOne staff or are they crowdsourced? | Pentesters are not HackerOne employees. Tests are conducted by our community. We have identified in our community those with existing professional pentesting experience.
1515
We're looking for something that indicates that we had the assessment done and the status of the application at the end of the assessment retest period, without the detail for issues that were identified and corrected. Can you produce an abridged version with that information? | Yes, we offer a letter of attestation for our pentest assessments.
1616
I’m frustrated with traditional pentest firms including out-of-scope or insignificant vulnerabilities in reports. We have to explain these to customers and leadership all the time. Will the HackerOne pentest be different? | Pentesters look for coverage of the scope rather than just focusing on impactful vulnerabilities as in a bug bounty program. Pentest best practices call for low and informative vulnerabilities to be reported. OWASP guidelines are followed by pentesters in web and mobile applications. <br><br>HackerOne’s bug bounty offerings may be more suitable for you if your priority is to find the most impactful and critical bugs.

docs/programs/product-offerings.md

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,10 +14,18 @@ HackerOne offers 5 different products that you can choose from:
1414
* HackerOne Pentests
1515

1616
### HackerOne Response
17-
Establish an ISO 29147 compliant disclosure policy to safely receive and act on vulnerabilities discovered by external third-parties. This welcomes a "See Something, Say Something" process that helps ensure that security reports end up with your security team instead of unreliable channels like social media.
17+
Establish an ISO 29147 compliant disclosure policy to safely receive and act on vulnerabilities discovered by external third-parties. This welcomes a "See Something, Say Something" process that helps ensure that security reports end up with your security team instead of unreliable channels like social media.
1818

1919
![overview-2](./images/overview-2.png)
2020

21+
<<<<<<< HEAD
22+
=======
23+
### HackerOne Challenge
24+
A private, project-based, and time-bound vulnerability assessment program. Challenges are perfect for organizations looking to supplement or replace traditional penetration tests with ethical hackers looking for severe vulnerabilities. Every Challenge includes a detailed report to help meet compliance requirements.
25+
26+
![overview-1](./images/overview-1.png)
27+
28+
>>>>>>> 6644bf47d6d8d2a0cda89a1719db9bc467243782
2129
### HackerOne Bounty
2230
A program where trusted hackers are incentivized to continuously test for critical vulnerabilities. Bounty programs can be private and invite-only or fully public, and all incentives will reflect the organization’s priorities.
2331

docs/programs/slack-shared-channels.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ You can join HackerOne’s Customer Slack workspace (https://hackerone-customer.
2222

2323
> **Note:** It’s your responsibility to inform HackerOne in a timely manner when a member’s access is to be revoked.
2424
25-
To join Hackerone’s Slack workspace as a guest:
25+
To join HackerOne’s Slack workspace as a guest:
2626
1. Click the Join Now button in your Slack invitation email.
2727

2828
![Join HackerOne on Slack screen](./images/slack-shared-channels-1.png)

0 commit comments

Comments
 (0)