Earn United Airlines Award Miles For Finding Bugs
Written by Sue Gee   
Sunday, 17 May 2015

A new Bug Bounty program has been launched. Instead of cash United Airlines is offering Award miles in return for finding vulnerabilities. But looking for ones in on-board systems or avionics is strictly off limits.

unitedairlines

 

Like most other bug bounty programs reward can only be claimed by the first researcher to submit a report about a new bug and the researcher submitting the bug must not be the author of the vulnerable code. An extra eligibility criteria is that the researcher must be a member "in good standing" of United Airline's MileagePlus rewards scheme and the payouts - which range from 50,000 to 1,000,000 according to the severity of the bug are in "award miles". But if you don't want to become a frequent flyer there are other goods and services that they can be exchanged for. 

usrewards

 

Authentication bypass, cross-site request forgery or cross-site scripting, remote code execution and the ability to brute force reservations, MileagePlus numbers, PINs or passwords are among the bugs that are eligible for submission.

On the other hand bugs in avionics are not eligible for submission so looking for stack overflow in airlines, see Reboot Your Dreamliner Every 248 Days To Avoid Integer Overflow, won't earn you any airmiles.

There's also list of actions that:

will result in permanent disqualification from the bug bounty program and possible criminal and/or legal investigation

including: 

  • Brute-force attacks
  • Code injection on live systems
  • Disruption or denial-of-service attacks
  • The compromise or testing of MileagePlus accounts that are not your own
  • Any testing on aircraft or aircraft systems such as inflight entertainment or inflight Wi-Fi
  • Vulnerability scans or automated scans on United servers

As it's a new program there are like to be some bugs waiting to be discovered. The procedure it to submit them by email describing the nature of the bug along with any steps required to replicate it, as well as pertinent applications, programs or tools used to discover the bug. A report including screenshots is appreciated and one item of vital info, together with name and phone number or your MileagePlus number.

 unitedsq

Banner


Apache Fury Adds Optimized Serializers For Scala
31/10/2024

Apache Fury has been updated to add GraalVM native images and with optimized serializers for Scala collection. The update also reduces Scala collection serialization cost via the use of  encoding [ ... ]



Ai-Da's Portrait of Alan Turing At Auction
01/11/2024

Sotheby's Digital Art Day Action, now underway, features a large-scale portrait of  Alan Turing created by Ai-Da, the humanoid robot artist whose work, including this canvas, was exhibited at the [ ... ]


More News

 

espbook

 

Comments




or email your comment to: comments@i-programmer.info

Last Updated ( Sunday, 17 May 2015 )