Live data from Hacker News

Beg Bounties (2021)

troyhunt.com

61–70 of 174 posts

Re: Beg Bounties (2021)

#61
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

Bad behaviour should not be tolerated just because it comes from the third world

Re: Beg Bounties (2021)

#62
post #5

I get a lot of these but I have to admit I have a few favourites: 1. "I can download archives of your public mailing list from your website!" 2. "I can download tarsnap source code from your website!" 3. "I can telnet to port 25 on your mail server and send you an email!" I have the misfortune of being an early offerer of bug bounties -- and being unusual in offering bounties for all bugs, not just security bugs -- w…

[deleted]

Re: Beg Bounties (2021)

#63

Earlier quoted context omitted.

Inadvertent public buckets leading to data loss is what created those hoops. Trying to take the ammo out of the footgun. https://www.theregister.com/2022/12/14/aws_simple_storage_se...

But why would they upload private data to S3 in the first place? I’m just not understanding the context here.

Because half the world is below average.

Re: Beg Bounties (2021)

#64
post #62
post #5

I get a lot of these but I have to admit I have a few favourites: 1. "I can download archives of your public mailing list from your website!" 2. "I can download tarsnap source code from your website!" 3. "I can telnet to port 25 on your mail server and send you an email!" I have the misfortune of being an early offerer of bug bounties -- and being unusual in offering bounties for all bugs, not just security bugs -- w…

[deleted]

[deleted]

Re: Beg Bounties (2021)

#65

Earlier quoted context omitted.

Oh yeah... I don't run a docker registry, but Amazon feels it necessary to remind me periodically that FreeBSD releases are public AMIs, and their filesystem images are public, and I have publicly readable data in S3 (which is mandatory in order to create an AWS Marketplace listing). So much "yes I know it's supposed to be that way".

It’s so bizarre that every time I upload something to S3 I have to jump through a hoop to make it publicly readable and Amazon displays a massive warning sign. Like the only thing I use S3 for is hosting open source software binaries. Maybe there’s a use case for restricting access, but I don’t even know what that would be.

You really need to think carefully about whether you want to expose an S3 bucket publicly. There are probably some valid reasons out there, but if you're not an AWS expert, it's likely that you're making a mistake. If I find out the name of your bucket I could cost you thousands of dollars of egress tonight before you wake up in the morning. It's _especially_ likely to happen to hosters of open source binaries because of people absent-mindedly downloading artifacts from CI jobs. No malice required. They make the mistake but you pay the bill.

Re: Beg Bounties (2021)

#66

> I don't know how many disclosures I've done ... (100+, surely), but I have never, ever - not even once - asked for money. But Hammad isn't me I agree with everything in this post except this line. It's nice that the author doesn't need the money, but some people do. To me, the problem is not sharing after the answer is no, or not asking up front, not the fact someone is asking for money.

I don’t think asking for money is the issue- it’s the overall handling of the situation on the researcher’s side.

If you’re only trying to collect bounties, you should go to a bug bounty website and work on sites that are explicitly soliciting bounties - that way you aren’t wasting your time finding vulnerabilities on sites that have no interest in paying out, and you can see which types of vulnerabilities are in- and out of scope.

On the other hand, I don’t think it’s particularly rude to shoot an email over explaining the vulnerability while at the same time requesting compensation. But gating information on the vulnerability behind a request for compensation is not appropriate.

Re: Beg Bounties (2021)

#67

> Alas, all reasonable measures were exhausted without response, I loaded the data into Have I Been Pwned (HIBP) and then they took notice Every single time. They don't really care about users, their safety and privacy. They care about legal liability and not looking foolish in public. It seriously makes me wish people would just publish vulnerabilities straight up complete with exploit source code so they'd have lit…

And when they respond, they will often make things go sooo slow. Like how the huge Apple Safari issue took a year from reporting to public disclosure.

Re: Beg Bounties (2021)

#68
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

We've had a handful of these that we've paid out for small issues over the years. Things that are _technically_ security issues, but not something that affect us or are exploitable in a meaningful way. $50 a few times a year is stupid cheap to build a reputation of actually paying out security researchers. Among the junk, we've had a few legit bounties submitted. That alone is worth the noise these "beg bounties" cre…

How many of the legit bounties have been withheld until you paid?

Re: Beg Bounties (2021)

#69
I remember when I was a teenager I found a huge security flaw in a website: they allowed to include any PHP file passed as a query string parameter, and that file could be a remote one too.

They didn't listen to me and I found that offensive, so I used the flaw to get access, and leave a message on their FTP server. I didn't destroy nor steal any data. They responded by reporting the incident to the police.

Re: Beg Bounties (2021)

#70
post #61
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

Bad behaviour should not be tolerated just because it comes from the third world

Not tolerated but it should be understood. Lots of developers would do morally dubious things for a 'life-changing' amount of money. If you live in a very poor country that isn't a large sum compared to a Western salary.
Post reply on HN