- Sep 10, 2010
- 11,818
- 26,660
I would disclose the vulnerability responsibly by contacting the company and giving them reasonable time to fix the issue before making it public.Say you find an exploit and can exploit it for profit. and you know you can get away with it.
Would you exploit it for max profit? or would you report it to the company and hopefully have a nice reward?
![]()
In any case, I wouldn’t exploit the bug directly. I could still benefit from it either through a bug bounty or by creating a video that explains the process for others to learn from (ofcourse, after the bug has been fixed, or the time has passed).