Earlier quoted context omitted.
apologies, just a vc firm
The guidelines require using the same title on HN as is on the original post.
Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
31–40 of 112 posts
Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#32Earlier quoted context omitted.
I keep getting emails with the content like: "I found a critical bypass vulnerability in your app what is the appropriate channel to disclose it, and do you have a bounty program?" I tried engaging and replying to them, and it inevitably turns into: "Yeah, we don't actually have the vulnerability, but you are totally vulnerable, just let us do a security audit for you". I have a pre-written reply for these kinds of m…
From the looks of it, they actually asked for a way to report.
Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#33Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#34> Their initial reply from the CEO: "I would love to hear what the vulnerability is, but I assume you want to get paid for it. Is that the play?" Well that’s pretty damning.
I keep getting emails with the content like: "I found a critical bypass vulnerability in your app what is the appropriate channel to disclose it, and do you have a bounty program?" I tried engaging and replying to them, and it inevitably turns into: "Yeah, we don't actually have the vulnerability, but you are totally vulnerable, just let us do a security audit for you". I have a pre-written reply for these kinds of m…
I get tons of these messages too and the ones that do include details are the kind of junk you get from free "website vulnerability scanners" that are a bunch of garbage that means nothing -- "missing headers" for things I didn't set on purpose, "information disclosure vulnerabilities" for things that are intentionally there, etc... You can put google.com into these things and get dozens of results.
Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#35Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#361. I didn't see mention of a bug bounty program giving limited authorization. How do independent researchers do this with legal safety? Especially when DoD is involved?
2. If a researcher discovered a vulnerability at a DoD contractor, and the contractor didn't seem to be resolving the problem, is there a DoD contact point that would be effective and safe for the researcher to report it?
Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#37Earlier quoted context omitted.
Yes, there are also many other lucrative illegal activities.
Isn't it also illegal to withhold knowledge of a vulnerability for payment? It sounds like it should fall under some variety of blackmail.
The system is already pretty bad because vendors underinvest in security, and then to fix it, researchers have to volunteer their time to investigate with no guarantee of payment. If the vendor could force researchers to hand over findings for free, nobody would want to do security research except hobbyists having fun. They're basically signing up for hours of tedious forced labor to explain vulnerabilities to the vendor.
I wish there was legislation that allowed the government to fine vendors for security vulnerabilities like this where the amount scales based on how much user data they leaked. And it could function like other whistleblower systems where a researcher who spots a leak can report it to the government and collect 50%. That way, if the vendor says, "We're not paying you," the researcher can turn around and collect the money from fines.
Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#38Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#39Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#40Two questions prompted by this disclosure: 1. I didn't see mention of a bug bounty program giving limited authorization. How do independent researchers do this with legal safety? Especially when DoD is involved? 2. If a researcher discovered a vulnerability at a DoD contractor, and the contractor didn't seem to be resolving the problem, is there a DoD contact point that would be effective and safe for the researcher…
In my experience it’s usually foreign nationals from third-world countries doing drive-by beg-bounty testing. Presumably they don’t much consider legality.