• Ever wanted an RSS feed of all your favorite gaming news sites? Go check out our new Gaming Headlines feed! Read more about it here.
  • We have made minor adjustments to how the search bar works on ResetEra. You can read about the changes here.

Theorry

Member
Oct 27, 2017
61,045
Microsoft is launching a new Xbox Bounty Program to reward gamers, security researchers, and anyone else who discovers security vulnerabilities in the Xbox Live network and services. Bounty rewards will range from $500 up to $20,000, and Microsoft notes there could even be higher payouts depending on the quality of the report and the vulnerability impact.

The biggest payouts will be handed out for critical remote code execution and elevation of privilege flaws, while security feature bypasses, information disclosure, spoofing, and tampering will all include rewards up to $5,000. As Microsoft is opening this up to gamers and anyone who has the skills to find flaws, it's expecting high-quality reports with a detailed write-up or video demonstration, and a clear proof of concept. Microsoft isn't looking for people to perform DDoS testing, social engineering attacks, or going too far on server-side execution issues.

Microsoft has run bug bounty programs for a number of its products over the years, including payouts of up to $250,000 for Windows 10 security bugs. This new Xbox Bounty Program comes just as Microsoft prepares to launch its Xbox Series X console and xCloud game streaming service. Both will operate on the Xbox Live network. Sony and Nintendo also accept security bug reports, with Nintendo rewarding up to $20,000 and Sony only providing a t-shirt as recognition.

 

CalamityPixel

Member
Oct 27, 2017
2,810
There's a bug where people kill me in videogames when I definitely killed them first.

Cash upfront please MS
 

kuroneko0509

Member
Oct 25, 2017
2,378
for some reason I thought Microsoft already have bounty program for xbox side. also lol sony with t-shirt reward
 

jelly

Banned
Oct 26, 2017
33,841
Always wondered how people cheated on Xbox Live from the Halo 2 days, flying warthogs etc. I guess Microsoft knows people are cheating but the holes to allow it are there.
 
Oct 25, 2017
4,841
Always wondered how people cheated on Xbox Live from the Halo 2 days, flying warthogs etc. I guess Microsoft knows people are cheating but the holes to allow it are there.
Hacked consoles. Original Xbox and Xbox 360 have been hacked to run custom software.

Xbox One is currently not hackable. And although the PS4 is hacked, hackers are stuck on old firmwares that can't connect online and have found no way to upgrade to the latest. That's why you see no cheats on either Xbox One or PS4.
 

Kyrios

Member
Oct 27, 2017
14,659
Yeah a few companies do this and I think it's a pretty good idea just to find the gaps the teams overlook. Just getting a t-shirt is pretty hilarious though lol
 

Akai

Member
Oct 25, 2017
6,045
Always wondered how people cheated on Xbox Live from the Halo 2 days, flying warthogs etc. I guess Microsoft knows people are cheating but the holes to allow it are there.

By modifying/flashing their consoles, which gives you access to file systems and also more importantly lets you run any unassigned code.
 

jelly

Banned
Oct 26, 2017
33,841
So the console is more secure right as said above so this is mainly for PC connectivity to Xbox Live?
 

MasterOfNone

Member
Oct 27, 2017
198
I always feel like these bounties are really small for the bigger payouts, assuming that 20K is the highest payout possible that would mean that finding a critical bug that could expose your entire console to unpatchable piracy (thinking worst case scenario here) leading to potentially millions of dollars lost (exec thinking) only awards the person who found it 20K?

I'm thinking not a lot of serious hackers with real jobs will spend the excruciating amount of hours finding a big loophole in security for a 20K best case scenario bounty.
 

bsigg

Member
Oct 25, 2017
22,556
I always feel like these bounties are really small for the bigger payouts, assuming that 20K is the highest payout possible that would mean that finding a critical bug that could expose your entire console to unpatchable piracy (thinking worst case scenario here) leading to potentially millions of dollars lost (exec thinking) only awards the person who found it 20K?

I'm thinking not a lot of serious hackers with real jobs will spend the excruciating amount of hours finding a big loophole in security for a 20K best case scenario bounty.

Honestly the people/teams that will be going after this are the ones that do it professionally. MS paid out $250k to a team that found a Windows 10 critical bug not too long ago.

Sony only offers a t-shirt if you find a bug like this lol
 
Oct 25, 2017
4,841
Sony is unable to provide a t-shirt if you are a resident of a country that faces United States export sanctions or trade restrictions. Sony assumes shipping costs of a "Finder" t-shirt to the vulnerability submitter. All other country and local taxes or fees are the responsibility of the researcher. All reward decisions by Sony are final.
You even need to pay for shipping for the Sony T-shirt!
 

Afrikan

Member
Oct 28, 2017
16,990
You even need to pay for shipping for the Sony T-shirt!

This is what happens when Sony is in 1st place.

We never learn.
unbelievable.gif