Never even heard of Prezi before this. If anything, they should be thanking this guy for all the free publicity.
That is if they're not paying him for it.
A Bug in the Bug Bounty
21–30 of 37 posts
Re: A Bug in the Bug Bounty
#22It seems the negative publicity you are getting is going to cost you more..
Re: A Bug in the Bug Bounty
#23Re: A Bug in the Bug Bounty
#24Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…
Re: A Bug in the Bug Bounty
#25"Sorry this security hole wasn't in our bug bounty but we'd like to give you the reward anyway. Please sign these legal documents and let us know if you find anything else."
There is so much you can do by just being reasonable. Like if Prezi said they can't officially acknowledge it under the bug program but can just pay out some sort of reward it makes way more sense.
Besides. If the bug was in the code under a subdomain that someone exposed source code it would be the same thing.
Re: A Bug in the Bug Bounty
#26Anecdotally I was snubbed at a younger age when the school district was looking for a security system to prevent manipulating school grades. My suggestion was to remove the disk pack (ok so it was a while ago) that contained student records while the students had access to the system via dialup, and replace it at night when the various accounting programs ran (attendance, grades, etc). Imagine my surprise when the co…
https://www.google.com/#q=expelled+for+reporting+security+bu...
Re: A Bug in the Bug Bounty
#27Earlier quoted context omitted.
I don't know about that: "from now on" seems to imply that in the future that will be the case.
Also: "and that their report triggers us to improve our code base". Closing port 8001 isn't quite improving the code base.
Re: A Bug in the Bug Bounty
#28Anecdotally I was snubbed at a younger age when the school district was looking for a security system to prevent manipulating school grades. My suggestion was to remove the disk pack (ok so it was a while ago) that contained student records while the students had access to the system via dialup, and replace it at night when the various accounting programs ran (attendance, grades, etc). Imagine my surprise when the co…
In today's world, you'd be expelled... https://www.google.com/#q=expelled+for+reporting+security+bu...
Re: A Bug in the Bug Bounty
#29Let's all agree that had Shubham not posted what had happened prezi wouldn't have done anything. This is just a PR stunt to save face.
First of all, we're still very thankful for pointing this issue out. The credentials you found were real threat. I agree when you write it was easy to exploit.
[...]
When we created the terms and conditions, we tried hard to add every web app which we have impact on, and where a reported issue is a value for us. At that time we weren't thinking of leaked password or such. In the past we turned down the bounty request of people finding issues in out-of-scope services. We had a lot internal discussions about your request: if we were about to pay, we couldn't justify our out-of-scope decisions for anyone else.
It seems reasonable from that email to assume they were discussing this incident seriously and thinking about how this would affect future bug bounties. I am willing to give them the benefit of the doubt unless you have a strong reason otherwise. When the matter was private between them and Shubham they issued a private apology and explanation. Now that Shubham has made the issue public they have issued a public apology and explanation. This is an appropriate response, not just a PR move.
Re: A Bug in the Bug Bounty
#30Why don't you just pay him for the service he provided you? Is your bounty that high that you can't afford to? It seems the negative publicity you are getting is going to cost you more..
To improve the program from now on we will reward bug hunters who find bugs outside of the scope provided [...] We will also retroactively check to see if other reports found issues that fall into this category.