Live data from Hacker News

Beg Bounties (2021)

troyhunt.com

101–110 of 174 posts

Re: Beg Bounties (2021)

#101
post #3

I run a domain for our community association. I had an “ethical hacker” discover that I had neglected to set up spf records for that domain. I had to deal with him sending a bunch of nasty emails to our other board members after I refused to pay him for his “discovery”. (Actually I offered him a cut of my salary as a board member, which at $0, came out to be… less than he was hoping for) I’ll definitely keep a link t…

As a general rule, you really do want to set up SPF, dkim and dmarc. Without them there’s a real vulnerability there.

The annoying case is when you have them correctly configured but are using ~all instead of -all so you still need to deal with the beg bounties.

Re: Beg Bounties (2021)

#102
post #81

Earlier quoted context omitted.

We've had a handful of these that we've paid out for small issues over the years. Things that are _technically_ security issues, but not something that affect us or are exploitable in a meaningful way. $50 a few times a year is stupid cheap to build a reputation of actually paying out security researchers. Among the junk, we've had a few legit bounties submitted. That alone is worth the noise these "beg bounties" cre…

I run a bug bounty program and I don't mind report for small issues. It's true that most report from "beg bounty" hunters are noise, but we've acted on some reports a few time. One time, in particular, a researcher broke something which alerted us to a serious issue, while not understanding themselves what they had found, we still paid a fair bounty on the finding since we would not have found the issue without the a…

In my experience paying out once to a bug hunter resulted in an avalanche of useless "beg hunter" reports in the following weeks. Understandably security researchers brag about their finds on their resume but that has the side effect that other guys apparently crawl those and start targeting you.

I'm not saying this is good or bad, but just a warning that you should be prepared to read a lot more reports once you start paying.

Re: Beg Bounties (2021)

#103
post #100

Earlier quoted context omitted.

There are a few reasons. 1. The first is literally the first example of the article: real/important vulnerability disclosures get confused with beg bounties which dont need to be acted on / are not serious (most of the time). That can cause real harm. 2. The second reason is the approach that the beg bounty uses: that of fearmongering. If the beg-bountier disclosed the vuln and asked for the bounty that would be ok,…

> 1. The first is literally the first example of the article: real/important vulnerability disclosures get confused with beg bounties which dont need to be acted on / are not serious (most of the time). That can cause real harm. I have a hard time sympathizing with this. Our project gets a handful of these "beg bounty" things a year; usually they're repeats -- SPF and "clickjacking" are common ones, but we also get o…

at $DAYJOB we get multiple beg bounties a week, it's a massive waste of everyone's time and it's literally never been a real issue.

Re: Beg Bounties (2021)

#104
post #90

I remember when I was a teenager I found a huge security flaw in a website: they allowed to include any PHP file passed as a query string parameter, and that file could be a remote one too. They didn't listen to me and I found that offensive, so I used the flaw to get access, and leave a message on their FTP server. I didn't destroy nor steal any data. They responded by reporting the incident to the police.

No criticism because teenagers do dumb things, but for anyone else it should be assumed that if you break into a system without permission, benignly or not, you run the risk of getting prosecuted for it.

Threat of prosecution can come even without breaking in. Vengeful and ignorant people will always be a thing. [1]

Missouri's governor threatened legal action against a reporter who found SSN were being leaked on a public web page accessible simply by clicking "View Source". The reporter "followed standard protocols for disclosing and reporting on the vulnerability, the governor is treating him as if he attacked the site or was trying to access the teacher’s private information for nefarious purposes" .

This pisses me off on so many different levels. The reporter told proper authorities and gave them time to fix it before he made the information public but MO's jack-wagon of a governor tried to pin blame on the reporter.

[1] https://www.theverge.com/2021/10/14/22726866/missouri-govern...

Re: Beg Bounties (2021)

#105
post #73

Earlier quoted context omitted.

Valuable lesson for a teenager to discover how people really are. I hope the police was more reasonable!

The police allowed them to contact my ISP to get my name and location, not that I was hiding or anything. Apart from that they just logged the incident and there was no follow-up.

[deleted]

Re: Beg Bounties (2021)

#106
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

[deleted]

Re: Beg Bounties (2021)

#107
post #104
post #90

Earlier quoted context omitted.

No criticism because teenagers do dumb things, but for anyone else it should be assumed that if you break into a system without permission, benignly or not, you run the risk of getting prosecuted for it.

Threat of prosecution can come even without breaking in. Vengeful and ignorant people will always be a thing. [1] Missouri's governor threatened legal action against a reporter who found SSN were being leaked on a public web page accessible simply by clicking "View Source". The reporter "followed standard protocols for disclosing and reporting on the vulnerability, the governor is treating him as if he attacked the s…

Threat of prosecution is of course always present, but the chance of that prosecution making it past the courts is significantly altered by actually committing the acts you might be accused of.

Re: Beg Bounties (2021)

#108

I remember when I was a teenager I found a huge security flaw in a website: they allowed to include any PHP file passed as a query string parameter, and that file could be a remote one too. They didn't listen to me and I found that offensive, so I used the flaw to get access, and leave a message on their FTP server. I didn't destroy nor steal any data. They responded by reporting the incident to the police.

It's the danger of good intents but still breaking the law. If a house is unlocked and you go in to prove it's unlocked, maybe leave a helpful note, you're still breaking in. Report and move on.

> If a house is unlocked and you go in to prove it's unlocked, maybe leave a helpful note, you're still breaking in.

What jurisdiction? I would think this was just trespass.

Re: Beg Bounties (2021)

#109
After reading this HN post in the morning, I've received one of those SPF ~all beg bounties via email today. It ends with:

From: whiteboxtesting01@gmail.com

> Waiting for your response and hoping for a bounty reward for responsibly disclosing this issue to your website. Furthermore, I may attempt to contact you again if I do not receive a response to ensure that my message has reached you.

Re: Beg Bounties (2021)

#110

Earlier quoted context omitted.

It's the danger of good intents but still breaking the law. If a house is unlocked and you go in to prove it's unlocked, maybe leave a helpful note, you're still breaking in. Report and move on.

> If a house is unlocked and you go in to prove it's unlocked, maybe leave a helpful note, you're still breaking in. What jurisdiction? I would think this was just trespass.

IIRC some jurisdictions consider any force at all - such as pushing an already-open door further open - to be sufficient to make it B&E rather than simply trespassing.
Post reply on HN