So here seems like as good a thread as any. What do you do when you think a company would just fix the bug based on your report and not pay out anything? I have seen so many bugs in the wild like this. For example a site in the uk where I can get access to any account I wish. Are there any data protection laws that would provide leverage? How would you make first contact with a company that doesn't advertise a bug bo…
No, that email doesn't seem okay at all. That's extortion. A company has every right to not offer a bug bounty, and to fully prosecute you for trying to find a vulnerability (you can quibble about what "trying to find a vulnerability" means, but they have the right, like it or not). You have no right to demand payment for a perceived vulnerability in a company's infrastructure, even if they have a bug bounty program.…
What if you aren't a professional security researcher, though? I'm sure there are plenty of underpaid people out there who stumble onto bugs like this every so often. Yes, asking the company to give you money on threat of revealing the bug is definitely extortion, but you are assuming a little too much in this case I believe. Some people may truly need the money.