Beg Bounties (2021)
troyhunt.com
Beg Bounties (2021)
1–10 of 174 posts
Re: Beg Bounties (2021)
#2Re: Beg Bounties (2021)
#3I’ll definitely keep a link to this for next time this happens.
Re: Beg Bounties (2021)
#4Re: Beg Bounties (2021)
#51. "I can download archives of your public mailing list from your website!"
2. "I can download tarsnap source code from your website!"
3. "I can telnet to port 25 on your mail server and send you an email!"
I have the misfortune of being an early offerer of bug bounties -- and being unusual in offering bounties for all bugs, not just security bugs -- which means that Tarsnap shows up pretty quickly when bounty beggars start looking for targets.
Re: Beg Bounties (2021)
#6Re: Beg Bounties (2021)
#7I get a lot of these but I have to admit I have a few favourites: 1. "I can download archives of your public mailing list from your website!" 2. "I can download tarsnap source code from your website!" 3. "I can telnet to port 25 on your mail server and send you an email!" I have the misfortune of being an early offerer of bug bounties -- and being unusual in offering bounties for all bugs, not just security bugs -- w…
yeah man, i know that. i made it public.
i eventually had to take it down, just to stop the flood of beg bounties telling me about it.
Re: Beg Bounties (2021)
#8I guess I wonder about the opposite side of this. While I hate the beg bounty people as well, I don't think security researchers should work for free. I have found several security vulnerabilities that I have never reported to the company because their security policy was basically "send us everything you found for free and we won't give you any credit".
I agree. The OP comes across a bit gatekeepy to me. Not everyone has made a big name for themselves yet.
How are you supposed to find customers in the first place? Gotta start somewhere.
Quality of the findings is orthogonal to asking for compensation.
There will always be people asking for money without providing value. But I don’t think we should throw the baby out with the bath water because of it.
Re: Beg Bounties (2021)
#9I guess I wonder about the opposite side of this. While I hate the beg bounty people as well, I don't think security researchers should work for free. I have found several security vulnerabilities that I have never reported to the company because their security policy was basically "send us everything you found for free and we won't give you any credit".
if you're doing un-asked-for work, you can't expect to get paid
Re: Beg Bounties (2021)
#10I get a lot of these but I have to admit I have a few favourites: 1. "I can download archives of your public mailing list from your website!" 2. "I can download tarsnap source code from your website!" 3. "I can telnet to port 25 on your mail server and send you an email!" I have the misfortune of being an early offerer of bug bounties -- and being unusual in offering bounties for all bugs, not just security bugs -- w…
my favourite is "your docker registry is publicly accessible" yeah man, i know that. i made it public. i eventually had to take it down, just to stop the flood of beg bounties telling me about it.
So much "yes I know it's supposed to be that way".