Live data from Hacker News

Beg Bounties (2021)

troyhunt.com

71–80 of 174 posts

Re: Beg Bounties (2021)

#72
Throwaway account for obvious reasons. I've been employed as a triager on two primary bug bounty platforms for over seven years. The circumstances are distressing and carry tangible real-life consequences. I'm open to answering questions within my personal comfort zone.

Re: Beg Bounties (2021)

#73

I remember when I was a teenager I found a huge security flaw in a website: they allowed to include any PHP file passed as a query string parameter, and that file could be a remote one too. They didn't listen to me and I found that offensive, so I used the flaw to get access, and leave a message on their FTP server. I didn't destroy nor steal any data. They responded by reporting the incident to the police.

Valuable lesson for a teenager to discover how people really are. I hope the police was more reasonable!

Re: Beg Bounties (2021)

#74
post #70
post #61

Earlier quoted context omitted.

Bad behaviour should not be tolerated just because it comes from the third world

Not tolerated but it should be understood . Lots of developers would do morally dubious things for a 'life-changing' amount of money. If you live in a very poor country that isn't a large sum compared to a Western salary.

It’s not hypothetical. Lots of developers do do morally dubious things in the west for large amounts of money!

Re: Beg Bounties (2021)

#75
I get that Troy is probably tired of receiving beg bounties, but as a security researcher himself, I find this post a bit distasteful and discouraging towards the people who could as well be on their way to finding bigger vulnerabilities.

Reports on lack of SPF/DMARC records on security headers can be annoying, and often false, because there are some legitimate cases an SPF record with `~all` is necessary, or you have to have a permissive CSP for whatever reason.

I would have just deleted their email and moved on.

Re: Beg Bounties (2021)

#76
post #73

I remember when I was a teenager I found a huge security flaw in a website: they allowed to include any PHP file passed as a query string parameter, and that file could be a remote one too. They didn't listen to me and I found that offensive, so I used the flaw to get access, and leave a message on their FTP server. I didn't destroy nor steal any data. They responded by reporting the incident to the police.

Valuable lesson for a teenager to discover how people really are. I hope the police was more reasonable!

The police allowed them to contact my ISP to get my name and location, not that I was hiding or anything.

Apart from that they just logged the incident and there was no follow-up.

Re: Beg Bounties (2021)

#77
post #75

I get that Troy is probably tired of receiving beg bounties, but as a security researcher himself, I find this post a bit distasteful and discouraging towards the people who could as well be on their way to finding bigger vulnerabilities. Reports on lack of SPF/DMARC records on security headers can be annoying, and often false, because there are some legitimate cases an SPF record with `~all` is necessary, or you hav…

You receive 20 mails each day and when you delete them you receive follow ups. You receive emails getting angry and the tone shifts to threats (as if the bug they are reporting warrants it).

These bury any legitimate reports. We have missed a legit one because of the sheer amount of beggers at some point. Luckilty the person on the other end contacted us again and was understanding that we missed it.

And there are some who do not disclose and act like there is a really critical issue, fishing for replies first and then dropping a pile of shit as a critical security issue.

I'm also fed up with these.

Re: Beg Bounties (2021)

#78
post #77
post #75

I get that Troy is probably tired of receiving beg bounties, but as a security researcher himself, I find this post a bit distasteful and discouraging towards the people who could as well be on their way to finding bigger vulnerabilities. Reports on lack of SPF/DMARC records on security headers can be annoying, and often false, because there are some legitimate cases an SPF record with `~all` is necessary, or you hav…

You receive 20 mails each day and when you delete them you receive follow ups. You receive emails getting angry and the tone shifts to threats (as if the bug they are reporting warrants it). These bury any legitimate reports. We have missed a legit one because of the sheer amount of beggers at some point. Luckilty the person on the other end contacted us again and was understanding that we missed it. And there are so…

Quoted from the post:

> It was _immediately_ clear that Hammad was going to beg for a bounty, but it was a quiet Saturday night here and I thought it would be entertaining to see just how far down the rabbit hole he wanted to go. So, I responded, positively:

I suppose most of these useless bounty reports are quite easy to tell.

From the comment above:

> 20 mails each day

If you receive 20 mails a day to your security email address, then, perhaps it's time to setup a proper bug bounty program? They will weed out low impact vulnerabilities and only elevate the reports above a certain threshold. Isn't this a solved problem already?

Re: Beg Bounties (2021)

#79
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

I've received those mails a few times and while I agree with you to some extent, the way they are often formulated feels closer to "nice store you have here, shame if something were to happen to it!" -- as in, what is this person going to do if I don't pay up? That does not seem ethical to me.

Re: Beg Bounties (2021)

#80
I understand the problem, beggars add noise to an important contact signal point…

But this idea that people 'did actually already do the "work" for free' so don't deserve remuneration… isn't great.

Lot's of people do spec work to try and get paid, or to get more work. The recipient is free to negotiate, rebuff or simply ignore it, but this idea that time sunk is valueless is unhelpful.

Not defending "Hammad" here. If you do spec security work you need to lead with what you've got, even if that's just a rough CVE severity rating, and your price. But I think I'd rather have people checking my configuration and taxing me for my errors than not to know at all.

Post reply on HN