If paying out bounties was easy I would do it all via email; but as you said it’s almost impossible to do (unless you are maybe bigcorp and have a team just for that)
If paying out bounties was easy I would do it all via email; but as you said it’s almost impossible to do (unless you are maybe bigcorp and have a team just for that)
Outsourcing all that mess is a great use of money.
- Starting scenario: no way to contact a company outside of H1 (or some other managed programme)
- The company is compromised, their customer support has no idea what this means, they have no security.txt or any other security contact
- I have explicitly told H1 to just forward it with no bounty, I don't want a bounty, only remediation, I do not care about a bounty or any reward
- H1 closes as "not eligible" and tells me to not submit stuff I can't prove it's my compromise by putting my username on it
- Corporate server is still compromised and being used as a proxy to brute force my services