193.145 Bug Bounty Program of TU Wien
This course is in all assigned curricula part of the STEOP.
This course is in at least 1 assigned curriculum part of the STEOP.

2024S, UE, 2.0h, 3.0EC
TUWEL

Properties

  • Semester hours: 2.0
  • Credits: 3.0
  • Type: UE Exercise
  • Format: Blended Learning

Learning outcomes

After successful completion of the course, students are able to search for information security shortcomings and vulnerabilities in complex IT systems, to document their findings and to rate the severity of the documented issues.

Subject of course

Similarly to a bug bounty program, students will be tasked with identifying and reporting security vulnerabilities on TU Wien's IT systems. Participants will gain hands-on experience in security testing, including web application security, network security, and software security. The course will provide insights on standard tools and techniques to identify and exploit security vulnerabilities, as well as documenting and reporting their findings. Additional topics will include legal and ethical aspects of security testing, responsible disclosure, mitigation of security vulnerabilities, standard metrics for rating the severity of security issues (CVEs), and the adoption of bug bounty programs in the industry.

Teaching methods

The course will offer a combination of 1-2 in-person lectures and online learning materials. The in-person lectures will introduce the course, rules, scope, and ethical aspects of the program. Furthermore, academic and industry experts will share their experiences and insights on vulnerability assessment and bug bounty programs. The evaluation will be based on the students' reports on their findings and the methodology employed.

Mode of examination

Immanent

Additional information

Inspired by the bug bounty program of Stanford University.

Please see the e-learning course for the details and rules.

ECTS-Breakdown:

Description                       ECTS  Hours
---------------------------------------------
Preparation                       0.04    1.0
Lecture                           0.16    4.0
Practical Project Work            2.52   63.0
Preparation of Seminar Paper   0.28    7.0
---------------------------------------------
Total                             3.00   75.0

Lecturers

Institute

Course dates

DayTimeDateLocationDescription
Fri11:00 - 13:0022.03.2024Seminarraum FAV 01 A (Seminarraum 183/2) Prelecture meeting
Fri09:00 - 16:0014.06.2024Seminarraum FAV 01 A (Seminarraum 183/2) Seminar

Examination modalities

Based on participation in the course and the final report + presentation.

Course registration

Begin End Deregistration end
01.03.2024 00:00 21.03.2024 00:00 22.03.2024 00:00

Curricula

Literature

No lecture notes are available.

Previous knowledge

general interest in IT security

Language

English