Hacker News new | ask | show | jobs
by thaumasiotes 2302 days ago
What would you expect HackerOne to do in the situation you describe? You filed a duplicate report. All of the malfeasance you allege is coming from Portswigger.
1 comments

No idea which one it was, or both. 23K isn't something to sneeze at though, and would be plenty of incentive for the folk at Portswigger to work with douchebags like whoever this shubby dude is in order to collect these bounties.

24K for one bounty... or sell $299 licenses to nerds.. hmm, which one is more profitable...

...the second one is significantly more profitable.
Yeah I bet. It would be interesting to see how many U.S. DoD networks have been compromised with Burp Proxy.