ÎÒÃÇÖØÊÓ×ÊѶ°²È«£¬²¢ÖÂÁ¦ÓÚ³ÖÐøÇ¿»¯ÎÒÃǵÄÍøÕ¾·À»¤ÄÜÁ¦¡£Èç¹ûÄúÊÇ×ʰ²Ñо¿ÈËÔ±£¬²¢ÔÚÎÒÃǵÄÍøÕ¾Öз¢ÏÖDZÔÚ©¶´£¬ÎÒÃdzÏÖ¿ÑûÇëÄúЭÖú»Ø±¨£¬ÎÒÃǽ«¶Ô·ûºÏ×ʸñµÄ»Ø±¨Ìṩ½±Àø¡£

 

 

¼Æ»­·¶Î§

±¾Â©¶´»Ø±¨¼Æ»­½öÊÊÓÃÓÚÏÂÁÐÍøÓò£º

 

»Ø±¨ÄÚÈݽöÏÞÓÚÒÔÉÏÍøÕ¾ÖÐËùÊôµÄ¹«¿ªÒ³ÃæÓ빦ÄÜ¡£ÇëÎð¶Ô¹«Ë¾ÄÚ²¿ÏµÍ³¡¢µÚÈý·½·þÎñ»ò·Ç¹«¿ª¶Ëµã½øÐвâÊÔ£¬AUO ÓÐÈ¨ËæÊ±¸ü¸ÄÕâ·ÝÇåµ¥£¬Ë¡²»ÁíÐÐ֪ͨ¡£

 

 

×ʸñÌõ¼þ

Ϊȷ±£ºÏ·¨ÐÔÓëÉó²é±ãÀû£¬±¾¼Æ»­½ö½ÓÊܾßÖлªÃñ¹ú¹ú¼®ÇÒÄêÂú 18 ËêÖ®²ÎÓëÕß¡£²ÎÓëÕßÐèÓڻر¨Ê±ÌṩÓÐЧÉí·ÝÖ¤Ã÷Îļþ£¬ÒÔ¹©×ʸñºËʵ¼°ºóÐø½±Àø·¢·Å¡£

 

¿É½ÓÊÜ֮©¶´ÀàÐÍ (°üº¬µ«²»ÏÞÓÚ)£º

 

  • ¿çÕ¾½Å±¾¹¥»÷ (XSS)
  • ¿çÕ¾ÇëÇóαÔì (CSRF)
  • Éí·ÝÑéÖ¤ÈÆ¹ý
  • ȨÏÞÌáÉý
  • ËÅ·þÆ÷¶Ë³Ìʽ´íÎó (ÈçÔ¶¶Ë³ÌʽÂëÖ´ÐС¢SQL Injection)
  • Ãô¸Ð×ÊѶй© (ÈçδÊÚȨ´æÈ¡µÄ¸ö×Ê¡¢É趨µµ)

 

²»ÔÚ½±Àø·¶Î§Ö®ÏîÄ¿

Ϊ¾Û½¹ÓÚÍøÕ¾°²È«±¾Éí£¬ÒÔÏÂÏîÄ¿½«²»ÁÐÈë½±Àø·¶Î§£º

 

  • ×Ô¶¯»¯¹¤¾ßɨÃè³öµÄµÍ·çÏÕ×ÊѶ
  • Clickjacking
  • HTTP headers ȱʧ (Èç CSP, HSTS µÈ)
  • ¹«¿ª×ÊѶÈç whois ×ÊÁÏ»ò metadata
  • ·þÎñÖжϲâÊÔ (Èç DoS ¹¥»÷)
  • Éç½»¹¤³Ì»òÍøÂ·µöÓã
  • 90ÌìÄÚ¹«¿ªµÄÁãʱ²î©¶´»ò¹¥»÷
  • δÏêÊö°²È«ÎÊÌâÓ°ÏìµÄ°²È«ÈõµãɨÃ豨¸æ
  • ȱ·¦¾ßÌå¸ÅÄîÖ¤Ã÷ (PoC) µÄÀíÂÛÐÔ·çÏÕ

 

 

»Ø±¨Ë³Î»Ô­Ôò

ÈôÓÐÁ½Î»»òÒÔÉϲÎÓëÕßͬʱ·¢ÏÖ²¢»Ø±¨Ïàͬ©¶´£¬ÎÒÃǽ«ÒÔ×îÏÈÍêÕûÌá½»»Ø±¨Õß×÷ΪÓÐЧ»Ø±¨È˲¢Ìṩ½±Àø¡£ºóÐø»Ø±¨ÕßËä¸Ðл²ÎÓ룬µ«²»ÔÙÁíÐÐÌṩ½±Àø¡£

 

 

ÔðÈνÒ¶Õþ²ß

ÎÒÃǹÄÀø¸ºÔðÈεÄ©¶´½Ò¶ÐÐΪ£¬²ÎÓëÕßÐë×ñÊØÒÔÏÂÔ­Ôò£º

 

  • ²»µÃÀûÓûò¹«¿ªÂ©¶´×ÊѶ¡£
  • ²»µÃ¶Ô·þÎñÔì³ÉÖжϻòÓ°ÏìÆäËûʹÓÃÕß¡£
  • ½öÏÞ½øÐзÇÇÖÈëÐԵIJâÊÔ¡£
  • Ò»¾­·¢ÏÖ©¶´£¬Ó¦Á¢¼´Í£Ö¹²âÊÔ²¢Ìá³ö»Ø±¨¡£
  • ËùÓÐͨ±¨µÄ©¶´×ÊѶÔÚδ¾­ÎÒÃÇÃ÷È·ÊéÃæÐí¿Éǰ£¬²»µÃÒÔÈκÎÐÎʽ¹«¿ª½Ò¶£¬°üÀ¨µ«²»ÏÞÓÚÉ罻ýÌå¡¢ÂÛ̳»òÆäËû¹«¿ªÆ½Ì¨¡£

 

 

»Ø±¨Á÷³Ì

Ç뽫ÄúµÄ·¢ÏÖ͸¹ýÒÔÏ·½Ê½»Ø±¨ÎÒÃÇ£º

 

  • µç×ÓÓʼþÐÅÏ䣺bugbounty@auo.com
  • »Ø±¨ÄÚÈÝÐë°üº¬£º
    • ·¢ÏÖÈÕÆÚÓëʱ¼ä
    • ÊÜÓ°ÏìÒ³Ãæ URL
    • ©¶´Ïêϸ˵Ã÷ÓëÖØÏÖ²½Öè
    • ²âÊÔʱËùʹÓõŤ¾ßÓë·¶Àý×ÊÁÏ (ÈôÓÐ)

 

¾­ÄÚ²¿Éó²éÈ·ÈÏΪÓÐЧ©¶´ºó£¬ÎÒÃǽ«ÒÀ·çÏյȼ¶Ìṩ½±Àø£¬²¢ÁªÏµÄú½øÐÐÉí·ÖÈ·ÈÏÓë½±Àø·¢·Å³ÌÐò¡£

 

 

½±Àø»úÖÆ

½±Àø½ð¶î½«ÊÓ©¶´µÄÑÏÖØÐÔÓëÓ°Ïì³Ì¶ÈÆÀ¹À£¬·¶Î§ÈçÏ£º

 

·çÏյȼ¶

½±Àø½ð¶î£¨ÐĄ̂±Ò£©

µÍ

1,000 – 3,000

ÖÐ

3,000 – 10,000

¸ß

10,000 – 30,000

ÎÒÃDZ£Áô½±Àø½ð¶î×îÖÕ½âÊÍÓëºË·¢È¨Àû¡£