Experience with PornHub's bug bounty: Scornhub
makthepla.net
makthepla.net
Our solution involved writing Apache Traffic Server plugins and achieving high throughput. Their solution involved using PHP to execute the demo cli tool that came with the library and pass it the content they wanted to encode.
But pentesters are not the ones paying for a HackerOne listing, those would be the companies, and perhaps the companies might not be so happy if HackerOne would publicly shame some of them.
There's plenty of guys out there who are searching for hacks like this because they need to feed their kids. I won't criticize them for selling bugs to nefarious entities.
Bug bounties aren't for guys like us who don't need the money.
Also, regardless of good intentions at the start, once the company has screwed you over. I am sure it is tempting to return the favor with the next vulnerability you find.
Naturally. Of course you must assume that some people don't.
It wasnt long ago that notifying a company that they had a vuln was an act that risked prosecution.
Bug bounties are a release valve. They are not a substitute for a job. They will never pay the same as crime. Writeups like this are not going to facilitate relationships with leaders in the security industry. This post and others like them are embarrassingly naive.
Yeah you used to risk prosecution for doing stuff like that, then the site owners realized how brain dead that was and now they are trying to have a normal relationship because it is a huge bonus for them, not because they give a shit about the people who helped them out.
In 2016, everyone deserves privacy and security on the internet. We know and understand the dangers of vulnerabilities better, and I think we should be capable of having some respect and suitably compensating those who do the right thing.
If you can make the internet a more secure place for us to live our lives and make enough to live out of it, more power to you.