Hacker News new | ask | show | jobs
by update 2850 days ago
> My favorite response though is still the "This is a duplicate from [random date six months ago]". Oh, so you're purposefully just leaving an XSS live on your corporate SSO? Makes sense!

Ug. I've submitted 2 bugs to Vimeo that gave this exact response. I even followed up a few months later to see if they'd patch it and they responded, "the developers are aware and working on it" ...

Seriously? Leaving 2 XSS bugs open on your website that you run a bug bounty program for?? for a year?

I really wish hackerone would punish this sort of behavior as it's a waste of every hacker's time to find a bug, write a report, only to be told it's a year old known bug so it's not eligible for a bounty.

1 comments

I found an submitted a bug once through bugcrowd to a very well known company where a session cookie could be used for complete account takeover even after the user had signed out etc. I was blown away when I got the "duplicate" response for a submission that was almost a year old. I wonder if they've ever fixed it...