Live data from Hacker News

I found Prezi's source code

blog.shubh.am

31–40 of 266 posts

Re: I found Prezi's source code

#32

I think they acted pretty fairly by pointing out that it's the logging in that they have issue with. Although it's not as satisfying, I think Shubham could have submitted the link and credentials to Prezi without actually accessing the repo. In particular, the report email contains the snippet "... I explored the nexus console to confirm that ..." and I can understand Prezi not wanting to encourage pen testers to exp…

> I think they acted pretty fairly

They absolutely didn't.

I don't get how there seems to be absolutely no human side to these cases.

Guy discovers critical vulnerability and could have completely fucked the company over. Instead he responsibly reports it, and he gets back a big fuck you. How can you possibly think that's fair? The fact that it's out of scope only means they should give him an out of scope reward - much higher!

Saying he could have not checked the credentials is a bit silly, because if the credentials were invalid (quite likely), it goes from CRITICAL to MINOR.

And isn't the entire point in bug bounties to encourage pen testers to explore your system? Sure, you don't really want them poking around your source control, but better that than black hats.

All of the above aside. They really couldn't spare $500 for someone who could have caused $millions of damage?

Re: I found Prezi's source code

#33
So let me get it straight, someone, aware of their bounty program or not, found their closed SOURCE CODE, and is getting a T-Shirt? How much do you value your own source code? at least 10,000$ right? ;) (probably much, much more) who cares about the scope, if someone found my wallet on the street which had 10,000$ in it, I would give them a bit more than a T-Shirt, I would buy them a whole wardrobe.

Think if someone found the source code for Windows / Office / Photoshop, without any bounty program, and responsibly disclosed it to the respective companies. If he didn't walk away with nice amount of money, he could easily just put it in the nearest torrent site* without even feeling guilty (*this is wrong, and illegal, don't do it)

Re: I found Prezi's source code

#34

There should be some neutral third party non-profit that adjudicates bug bounties so that security researchers don't need to worry that their efforts will go to waste. Companies could sign on to using this third party and pay a fee and put up escrow for the service. This would motivate researchers to find bugs for those companies that utilize the service, knowing payment will be impartial.

That could be done with Bitcoin contracts, too.

Bitcoin is much easier (and faster) to acquire than to liquidate. I'd rather be paid in cash.

Re: I found Prezi's source code

#35
post #10

It was out of scope. The rules are pretty clear: http://prezi.com/bugbounty/ and he broke at least two of them. And it seems like he knew it was out of scope when he submitted it too: "I had spent a total of 2 hours sifting and crawling through their services which were in scope , but wanted to see if I could locate any other subdomains..." Now I think Prezi should probably have paid him anyway because that's a prett…

So because it was out of scope it means that it could not have harmed the company so he should have just left it there?

Re: I found Prezi's source code

#36
post #20

Exhibit A of why having a scope for bug bounties is a terrible idea. What is the point of testing your app for esoteric bugs when your entire source code and passwords can be Google dorked?

Or for expanding the scope when you realize it's obviously too narrow.

Re: I found Prezi's source code

#37
post #21
post #18

Earlier quoted context omitted.

That said, he could have gone "gray-hat" and used the source to find in-scope bugs. Such a resource would be invaluable to an exploit author or bug bounty hunter.

Legally, I don't think there's much "gray" in stealing source code that doesn't belong to you.

I doubt it could have been called 'stealing' if he only accessed what was posted publicly by the authors themselves at the time.

Until he contacted Prezi, how could he be certain beyond any doubt that they weren't already aware of it? Could you explain that to me?

Re: I found Prezi's source code

#40
post #10

It was out of scope. The rules are pretty clear: http://prezi.com/bugbounty/ and he broke at least two of them. And it seems like he knew it was out of scope when he submitted it too: "I had spent a total of 2 hours sifting and crawling through their services which were in scope , but wanted to see if I could locate any other subdomains..." Now I think Prezi should probably have paid him anyway because that's a prett…

So because it was out of scope it means that it could not have harmed the company so he should have just left it there?

You're not entitled to a bounty just because you found a bug. Some companies offer these bounties and it's good that they do, but that doesn't mean every company is obliged to offer them, or that a company that offers bounties for some bugs is obliged to offer them for all bugs.
Post reply on HN