Most got dismissed.
One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved.
I doubt my situation is unique.
Most got dismissed.
One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved.
I doubt my situation is unique.
If you act in good faith, communicate clearly, and conduct yourself reasonably, most companies will work with you — even when you've technically wandered outside the neat boundaries of their risk-appropriate, regulatory-reviewed policy.
That isn't protection, of course. Eventually you'll encounter a bounty program run primarily by lawyers, procurement, or someone optimising a graph trend-line.
And we know what tends to happen next.
Those programs, and organisations, develop reputations. Researchers talk. Companies get discussed at conferences, in private groups and across the community, and some become informally blacklisted.
Microsoft is a useful recent example: researchers have publicly walked away from five-figure bounties to make a point. There are excellent people working there, but organisationally Microsoft has repeatedly struggled to engage with the security community in a way that feels collaborative, rather than adversarial. Unless you're one of their paid partners, intermingled in their ecosystem.
A lot of that seems to come down to incentives: somebody, somewhere, wants the numbers to look better.
That doesn't work particularly well in an industry that, like most industries, ultimately runs on relationships, trust and specialisation.
If a company marks something critical as informational, sometimes the most effective response is a CVSS parameter argument. It's a snarky comment:
"Okay — so if I find a way to abuse your own infrastructure to message your customers, trigger a major incident and create regulatory problems for your clients, you'd prefer I treat that as informational too, and instead just report it to regulators?"
Surprisingly often, that gets the issue reconsidered.
Have you annoyed an analyst? Maybe. Does it matter? Probably not. Neither of you will remember the exchange a week later, but you might have corrected a bad risk decision on their side and you'll see a positive outcome on your side. Mistakes happen.
I generally advise companies and hackers alike to follow Kiwicon's #1 rule.
It took down the entire application for all users and tenants, not just the tenant submitting the poisoned query.
I don't remember how much I was paid, a token amount for sure, but I was happy with any amount because it was a hobby and any payment was good for the CV.
Every application has a bug that can bring the whole application down for every user without owning a botnet? That comes often with a significant business cost, if someone exploits it. Many companies take them seriously. I have reported many as high and business has agreed. Not with HackerOne thought. If there is a bug where someone can make your whole product down with a single laptop isn't really something you can just ignore.
Which can be definitely high, if it can be triggered by giving specific URL, for example.
I think there is too much generalization happening here.
I think it would be the individual companies slowing things down, not the platform.
And they have hackerone employees pre-screen submissions and I had to tell them multiple times why my submission was valid.