Earlier quoted context omitted.
To be fair, there was a scope set, and the author was fully aware of it: > I had spent a total of 2 hours sifting and crawling through their services which were in scope, but wanted to see if I could locate any other subdomains, with the assistance of google. While I agree that he most certainly found a "bug" (perhaps flaw would be a better word), it was out of scope. And using credentials from an employee to log in…
That said, he could have gone "gray-hat" and used the source to find in-scope bugs. Such a resource would be invaluable to an exploit author or bug bounty hunter.
I found Prezi's source code
21–30 of 266 posts
Re: I found Prezi's source code
#22He plugged a huge issue for them, and they screw him over due to "scope"... That's their choice, but it still seems bureaucratic to me.
Re: I found Prezi's source code
#23Re: I found Prezi's source code
#24[1] Except for the totally illegal aspect, obviously. And the not-telling-them-their-source-is-open-to-the-world bit.
Re: I found Prezi's source code
#25> "Anyways, they did try and get it right, by emailing me an apology as well as responding to my constructive criticism. This blog post, is by no means attempting to discourage people from participating from Prezi’s bug bounty, but rather just a blog post about how finding Prezi’s source code was not eligible for their bug bounty." Passive aggressive much? I think he should have got a bounty -- if not the official on…
Probably doesn't want anybody pointing legal fingers at him for harming Prezi or something.
Re: I found Prezi's source code
#26There should be a database of these bounty programs that can tell you if a company pays or not, sort of like a credit bureau.
Re: I found Prezi's source code
#27It was out of scope. The rules are pretty clear: http://prezi.com/bugbounty/ and he broke at least two of them. And it seems like he knew it was out of scope when he submitted it too: "I had spent a total of 2 hours sifting and crawling through their services which were in scope , but wanted to see if I could locate any other subdomains..." Now I think Prezi should probably have paid him anyway because that's a prett…
The Finder provided tremendous value by discovering this issues and reporting it responsibly. He certainly should be rewarded with something more substantial than swag.
Would Prezi have preferred that the Finder just not report this issues?
Re: I found Prezi's source code
#28Earlier quoted context omitted.
That said, he could have gone "gray-hat" and used the source to find in-scope bugs. Such a resource would be invaluable to an exploit author or bug bounty hunter.
Legally, I don't think there's much "gray" in stealing source code that doesn't belong to you.
I thought the whole point of gray hat is that it's possibly illegal, but not downright "evil".
i.e. Stealing source code to fix bugs = gray, stealing source code to steal credit card info = black
Re: I found Prezi's source code
#29Exhibit A of why having a scope for bug bounties is a terrible idea. What is the point of testing your app for esoteric bugs when your entire source code and passwords can be Google dorked?
Case closed.