Earlier quoted context omitted.
This is quite common. If you run a security@ mailbox at a company, you're bound to receive hundreds of bug bounty/responsible disclosure requests because of known software quirks or other design choices. They'll cite precisely one CVE or HackerOne/BugCrowd report, and then proceed to demand a huge payment for a critical security flaw. I've seen reports that easily fail the airtight hatchway [0] tests in a variety of…
Yup, according to these "researchers" having robots.txt on your website is enough to warrant a CRITICAL vulnerability. No, I'm not joking. That's one of the reports I saw in November. I've also had to triage the claim that our site supposedly has a gazillion *.tar.xz files available at the root. All because the 404 handler for random [non-production relevant] paths is a fixed page with 200 response. As far as I'm con…
They freaked out when /admin/ returned permission errors, essentially a 404, because it was information leakage about admin functions of the website.