Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The U.S. Department of Defense’s 2019 “Hack the Proxy” challenge uncovered 31 valid vulnerabilities in government-facing proxy, VPN and virtual desktop systems. Eighty-one vetted hackers took part; the findings included one critical and nine high-severity vulnerabilities, and the DoD paid $33,750 in total bounties.

What was the “Hack the Proxy” challenge?

Announced by the Department of Defense on October 14, 2019, “Hack the Proxy” was the eighth DoD bug-bounty challenge. It ran from September 3 through September 18, 2019. U.S. Cyber Command sponsored the exercise, the Defense Digital Service supported it, and HackerOne coordinated submissions through its bug-bounty platform.

The challenge focused on government-owned proxies, virtual private networks (VPNs) and virtual desktops: internet-facing systems that can sit between public access and protected government networks. Cyber Command said testing these external touchpoints offered an outside-in view that complemented internal security work. A weakness in such an intermediary could expose information or provide a potential route toward internal resources.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did researchers find?

The DoD and HackerOne reported 31 valid vulnerabilities from 81 participating hackers. The 31 findings were vulnerabilities confirmed as valid, not a count of participants or an estimate of all weaknesses in DoD systems.

Severity reported Number of findings
Critical 1
High 9
Medium or low 21
Total 31

The severity mix matters: a total count alone does not show the potential impact of individual issues. One critical and nine high-severity findings were part of the results, while most of the reported vulnerabilities were classed medium or low.

How much did the challenge pay?

The DoD and HackerOne reported $33,750 in total bounty payments, with the highest single bounty at $5,000. CyberScoop reported that the top hunter earned $16,000. That is a separate figure from the largest individual bounty: it describes the top participant’s earnings across the challenge, not one award.

Who participated, and what did Cyber Command say?

The primary announcement said researchers took part from the United States, India, Turkey, Ukraine and Canada. The top hunter was based in the United States.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities
  • Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities
  • No Starch Press
  • ABIS BOOK

MSgt Michael Methven of U.S. Cyber Command’s Directorate of Operations described the objective as improving defensive readiness: “USCYBERCOM continuously advances defensive operations. Validating capabilities, closing previously unknown vulnerabilities, and enforcing standards improve our ability to conduct multi-domain military operations.” He also called the challenge “an important approach that leverages crowd-sourced talent for an outside-in view of our vulnerabilities.”

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the results show—and what they do not

The challenge demonstrated a bounded way to invite vetted outside researchers to look for weaknesses in specified, internet-facing systems. Its results apply to the targets and challenge period in 2019; they do not establish the current security of those systems, describe remediation outcomes, or show that the same program is running today.

For readers comparing government bug-bounty efforts, useful distinctions include which assets are in scope, how researchers are vetted, the severity mix, how disclosure and remediation are handled, how rewards are structured, and whether a platform partner coordinates reports. The 2019 figures offer a historical example, not a current benchmark for other programs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.