|
|
|
|
|
by mpeg
4574 days ago
|
|
I think it's ridiculous, I've reported similar "out of scope" bugs and got no bounty for them. Even worse are the companies that DON'T state any kind of bug bounty or instructions to report a security bug... I found a data leak issue in one of the web properties of an S&P 500 company last week and I'm not sure if I should report it, because I feel that if misunderstood it could have negative consequences for me; and not having a security contact means I can't be sure the person I'm talking to understands my motives. |
|