说在前面
如果你是一名白帽,挖洞可以说是一项不错的收入。大型一点的互联网企业都会有自己的应急响应中心,你可以去找他们对应业务(可以动的域名一般都会告知)下的漏洞提交到应急响应中心赚取收入。同时也可以关注响应公众号,蹲活动获取额外奖励。
说在前面:大厂奖励大,难度高;小厂难度小,奖励力度小。
各厂应急响应中心
360:https://security.360.cn/
阿里:https://asrc.alibaba.com/#/
蚂蚁金服:https://security.alipay.com/
菜鸟;https://sec.cainiao.com/
腾讯:https://security.tencent.com/
字节:https://src.bytedance.com/home
百度:https://bsrc.baidu.com/v2/#/home
美团:https://security.meituan.com/#/home
京东:https://security.jd.com/#/
小红书:https://security.xiaohongshu.com/
滴滴:http://sec.didichuxing.com/
T3出行:https://security.t3go.cn/#/home
荣耀:https://security.hihonor.com/src/#/home
小米:https://sec.xiaomi.com/#/
vivo:https://security.vivo.com.cn/#/home
oppo:https://security.oppo.com/cn/
唯品会:https://sec.vip.com/
有赞:https://src.youzan.com/
爱奇艺:https://security.iqiyi.com/#
Bigo:https://security.bigo.sg/#/
bilibili:https://security.bilibili.com/
斗鱼:https://security.douyu.com/#/welcome
贝壳;https://security.ke.com/
自如:https://zrsecurity.ziroom.com/
顺丰:https://sfsrc.sf-express.com/home
中通:https://sec.zto.com/home
58:https://security.58.com/
同程:https://sec.ly.com/
货拉拉:https://llsrc.huolala.cn/#/home
Boss;https://security.zhipin.com/
智联:https://src.zhaopin.com/
补天;https://www.butian.net/
途牛:https://sec.tuniu.com/
东方财富:https://security.eastmoney.com/
度小满:https://security.duxiaoman.com/index.html#/main
银联:https://security.unionpay.com/
敦煌:https://dhsrc.dhgate.com/
富友:https://fsrc.fuiou.com/home/index.html
瓜子:https://security.guazi.com/home
美丽联合;https://security.mogu.com/#/
魅族;https://sec.meizu.com/
陌陌:https://security.immomo.com/
网易:https://aq.163.com/
去哪儿;https://security.qunar.com/
新浪:https://sec.sina.com.cn/
微博:https://wsrc.weibo.com/
苏宁:https://security.suning.com/ssrc-web/index.jsp