where do you ACTUALLY submit vulnerabilities?

preview_player
Показать описание

Free Cybersecurity Education and Ethical Hacking
🔥YOUTUBE ALGORITHM ➡ Like, Comment, & Subscribe!
Рекомендации по теме
Комментарии
Автор

Seriously, sometimes you find a vulnerability or something weird on a company's website, they're not part of any bug bounty and don't have a security.txt file, it's always weird to reach out and tell them "Hey, I found a way to become admin BY ACCIDENT, please don't be angry".

JeffNoel
Автор

Thank you John for your countless inquests into making malware investigating an honorable and legit profession. Your videos are SO beneficial; and I just would like to personally say Thank you!

tmcarter
Автор

John you just answered one of the most common questions asked by CTF guys, Cyber Sec members and others on Reddit in r/hacking.

Many worry if they tell a company they're at risk of being sued themselves for pen-testing without permission. I mean if they attack a site to see if their suspicions are right regarding a vulnerability, I can see their concern.

repairstudio
Автор

This is such a simple concept John but could also be so useful!

TheBenSanders
Автор

you want to engage in educated arbitration - if bug bounty is a joke which it usually is then sell on zerodium and this may encourage bug bounties to get more realistic and accurate in terms of value

shephusted