Beg Bounties (2021)
71–80 of 174 posts
Re: Beg Bounties (2021)
#72Re: Beg Bounties (2021)
#73I remember when I was a teenager I found a huge security flaw in a website: they allowed to include any PHP file passed as a query string parameter, and that file could be a remote one too. They didn't listen to me and I found that offensive, so I used the flaw to get access, and leave a message on their FTP server. I didn't destroy nor steal any data. They responded by reporting the incident to the police.
Re: Beg Bounties (2021)
#74Earlier quoted context omitted.
Bad behaviour should not be tolerated just because it comes from the third world
Not tolerated but it should be understood . Lots of developers would do morally dubious things for a 'life-changing' amount of money. If you live in a very poor country that isn't a large sum compared to a Western salary.
Re: Beg Bounties (2021)
#75Reports on lack of SPF/DMARC records on security headers can be annoying, and often false, because there are some legitimate cases an SPF record with `~all` is necessary, or you have to have a permissive CSP for whatever reason.
I would have just deleted their email and moved on.
Re: Beg Bounties (2021)
#76I remember when I was a teenager I found a huge security flaw in a website: they allowed to include any PHP file passed as a query string parameter, and that file could be a remote one too. They didn't listen to me and I found that offensive, so I used the flaw to get access, and leave a message on their FTP server. I didn't destroy nor steal any data. They responded by reporting the incident to the police.
Valuable lesson for a teenager to discover how people really are. I hope the police was more reasonable!
Apart from that they just logged the incident and there was no follow-up.
Re: Beg Bounties (2021)
#77I get that Troy is probably tired of receiving beg bounties, but as a security researcher himself, I find this post a bit distasteful and discouraging towards the people who could as well be on their way to finding bigger vulnerabilities. Reports on lack of SPF/DMARC records on security headers can be annoying, and often false, because there are some legitimate cases an SPF record with `~all` is necessary, or you hav…
These bury any legitimate reports. We have missed a legit one because of the sheer amount of beggers at some point. Luckilty the person on the other end contacted us again and was understanding that we missed it.
And there are some who do not disclose and act like there is a really critical issue, fishing for replies first and then dropping a pile of shit as a critical security issue.
I'm also fed up with these.
Re: Beg Bounties (2021)
#78I get that Troy is probably tired of receiving beg bounties, but as a security researcher himself, I find this post a bit distasteful and discouraging towards the people who could as well be on their way to finding bigger vulnerabilities. Reports on lack of SPF/DMARC records on security headers can be annoying, and often false, because there are some legitimate cases an SPF record with `~all` is necessary, or you hav…
You receive 20 mails each day and when you delete them you receive follow ups. You receive emails getting angry and the tone shifts to threats (as if the bug they are reporting warrants it). These bury any legitimate reports. We have missed a legit one because of the sheer amount of beggers at some point. Luckilty the person on the other end contacted us again and was understanding that we missed it. And there are so…
> It was _immediately_ clear that Hammad was going to beg for a bounty, but it was a quiet Saturday night here and I thought it would be entertaining to see just how far down the rabbit hole he wanted to go. So, I responded, positively:
I suppose most of these useless bounty reports are quite easy to tell.
From the comment above:
> 20 mails each day
If you receive 20 mails a day to your security email address, then, perhaps it's time to setup a proper bug bounty program? They will weed out low impact vulnerabilities and only elevate the reports above a certain threshold. Isn't this a solved problem already?
Re: Beg Bounties (2021)
#79I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…
Re: Beg Bounties (2021)
#80But this idea that people 'did actually already do the "work" for free' so don't deserve remuneration… isn't great.
Lot's of people do spec work to try and get paid, or to get more work. The recipient is free to negotiate, rebuff or simply ignore it, but this idea that time sunk is valueless is unhelpful.
Not defending "Hammad" here. If you do spec security work you need to lead with what you've got, even if that's just a rough CVE severity rating, and your price. But I think I'd rather have people checking my configuration and taxing me for my errors than not to know at all.