Hacker News new | ask | show | jobs
by tommi 4915 days ago
I bet Blackhat Vulnerability Program would've payed lot more.
5 comments

For XSS? No.
With CPA + FB traffic on such a large scale, one could easy make $50k+ in a week with multiple CPA networks.
Knowing what little I do about the market for browser code execution vulnerabilities, I am very skeptical that there is a black hat market that pays 5 figures for XSS.
Of course it would. That's the idea of blackhat.
That goes against some people's conscience and they would find it immoral to do the wrong thing.

(i.e. you won't get that warm fuzzy feeling of doing the right thing with the blackhat market)

Do they give you a CC number you can use as much as you want?
Yeah, the OP is a really nice person. Because FB doesn't deserve this, not for $3.5k, maybe for $35k but more for around $350k to $3.5m. Guaranteed by contract.