I remember when I was a teenager I found a huge security flaw in a website: they allowed to include any PHP file passed as a query string parameter, and that file could be a remote one too. They didn't listen to me and I found that offensive, so I used the flaw to get access, and leave a message on their FTP server. I didn't destroy nor steal any data. They responded by reporting the incident to the police.
A good lesson to never do that - just use VPN to login to IRC to some hacking channel and report the issue there. Of course you should also do the white hat part in anonymized fashion.
Beg Bounties (2021)
151–160 of 174 posts
Re: Beg Bounties (2021)
#152I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…
That's one of the reasons that I don't play with scammers, anymore. Most of them live fairly miserable lives of poverty. That doesn't excuse them, but I don't feel it does me any good, to pile further misery on them, when it's just easier to walk away.
Usually the goal is to keep them away from real victims, to prevent further misery of more people.
Re: Beg Bounties (2021)
#153I understand the problem, beggars add noise to an important contact signal point… But this idea that people ' did actually already do the "work" for free' so don't deserve remuneration… isn't great. Lot's of people do spec work to try and get paid, or to get more work. The recipient is free to negotiate, rebuff or simply ignore it, but this idea that time sunk is valueless is unhelpful. Not defending "Hammad" here. I…
This makes no sense. Imagine someone shows up at your house, paints the fence and then asks you for compensation. They already did the work, but you never even asked for it. The same thing is happening here.
But you shouldn't expect to get the result for free.
Re: Beg Bounties (2021)
#154Earlier quoted context omitted.
That's one of the reasons that I don't play with scammers, anymore. Most of them live fairly miserable lives of poverty. That doesn't excuse them, but I don't feel it does me any good, to pile further misery on them, when it's just easier to walk away.
>to pile further misery on them Usually the goal is to keep them away from real victims, to prevent further misery of more people.
I have found that deliberately hurting others; regardless of whether or not they deserve it, tends to be corrosive to my mental well-being.
Re: Beg Bounties (2021)
#155e: I just noticed, this post was from 2 years ago. It should have (2021) in the header. --- I help run a bug bounty program, we get a lot of submissions. Way too many of them are zero or low effort. The SPF meme one definitely resonates with me, we get it a whole lot. Occasionally we will get someone who submits a half dozen variations of the same zero/low-effort report. When we turn around and deny them all (because…
Here is another perspective: I have been making money through bug bounties for the past 5 years (I'm a researcher on the major bug bounty sites and multiple private ones). More times than I can count, I have found major, non-low effort bugs, and the company will spend time deflecting, and I just won't end up getting paid. Luckily, this is less than 10% of the valid bugs I've found. I've learned to just move on after…
Keep in mind the bugs I found allows a lower-privileged group to not only access, but updated privileged information and other sections in the account with no user interaction. Definitely a security issue (multiple, in fact).
This is why security issues never get fixed and people like me stop looking. I suspect they will fix it and are again trying to find ways not to pay me.
Re: Beg Bounties (2021)
#156> Alas, all reasonable measures were exhausted without response, I loaded the data into Have I Been Pwned (HIBP) and then they took notice Every single time. They don't really care about users, their safety and privacy. They care about legal liability and not looking foolish in public. It seriously makes me wish people would just publish vulnerabilities straight up complete with exploit source code so they'd have lit…
If anything, my conclusion is that security researchers shouldn’t have any qualms about releasing vuln info. By all means, give the concerned party an opportunity to act in good faith, but when they invariably don’t, send it..
Re: Beg Bounties (2021)
#157> Want to be a bounty beggar? It's dead simple, you just use tools like Qualys' SSL Labs, dmarcian or Scott Helme's Security Headers, among others. Easy point and shoot magic and you don't need to have any idea whatsoever what you're doing You've described 90% of our cybersecurity department.
Want to be a developer? It’s dead simple. You can just install node.js and pull in a bunch of random dependencies.
Re: Beg Bounties (2021)
#158Most of the time, the company sent an angry response with threats of calling the police. I always thought this was stupid.
I would never look for security vulnerabilities on a company site, unless I'm hired to do so. The main issue is that you have no idea if what you are doing will affect a production sites.
Re: Beg Bounties (2021)
#159A bit off topic: I am genuinely surprised that he gets to blog (regular and micro via Twitter/X) with such a savage style. In many mega corps, even tech, they would eventually curtail this type of blogging. Steve Yegge is a pretty famous example where even Google was trying to curtail his blogging topics and style.
Being self-employed has some benefits - https://www.troyhunt.com/about/ .
This is very sleezy behavior and way worse than the guy he criticized did.
Re: Beg Bounties (2021)
#160I understand the problem, beggars add noise to an important contact signal point… But this idea that people ' did actually already do the "work" for free' so don't deserve remuneration… isn't great. Lot's of people do spec work to try and get paid, or to get more work. The recipient is free to negotiate, rebuff or simply ignore it, but this idea that time sunk is valueless is unhelpful. Not defending "Hammad" here. I…
This makes no sense. Imagine someone shows up at your house, paints the fence and then asks you for compensation. They already did the work, but you never even asked for it. The same thing is happening here.
1. Imagine a painter on the street, who made a quick painting of youand your partner in your natural state while being unaware of the process. Then he comes and asks if you are willing to pay and get it to yourself. No, you don't have the right to get it for free only because it was already painted.
2. Imagine that while you are on your walk, a guy comes to you and informs you that your bag was open and some stuff may have disappeared (dropped and/or stolen) from it. He went out of his way to detour and catch up to you (he had to run!) to report the issue. It was voluntary, but it is a good behavior. In physical world that alone should be rewarded (at least with sincere thanks). But if you are not willing to compensate, he has no duty to go spend even more of his time and energy in order to walk back, show you all the places where your stuff dropped and to stay and document all the details for your police/insurance application. He already did you a favor and is not required to put any more effort into it for free. It would be nice, but not a duty; especially because we are not talking about the private person or a hobby project, but about a company business. Discovering vulnerability is one thing, but properly writing and documenting it is a totally another expenditure of time, energy and opportunity cost. It is not free.