What Would You Do In This Situation?

Option 1 every time - in the long run, taking the honest path will help your business and reputation grow so you will end up making even more than with the exploit. Plus, it's the right thing to do.
 
I hear your point and would like to think I would've had a successful consulting business by now had I took Option 1 years ago. Problem what that is Option 2 was needed to be done to acquire a resume of sorts to show to other companies who I think are vulnerable now. Otherwise, I think they would have laughed me out of the building had I not actually took advantage of others and had some sort of "proof of concept" at work. I feel like now is a good time for me to what's out there for consulting since I've built up a rather extensive resume with exploits.

Option 1 every time - in the long run, taking the honest path will help your business and reputation grow so you will end up making even more than with the exploit. Plus, it's the right thing to do.
 
I think you're in a classic situation of blackhat-to-white/greyhat and I'm not talking about SEO. The whitehat security/hacking community is basically people who were hackers or convicted hackers that used their expertise and reputation to get big companies on their payroll. There's companies out there that look for software vulnerabilities to sell solely to governments. You can imagine they're doing pretty well. Also, I think you're underpricing yourself if you went for $2000 with option 1. If you're good, $10K/monthly should be a starting point.

Also, if you don't know already have this, I'd look to augment my skill-set with some programming/software penetration testing experience to have a more balanced outlook and resume.
 
Back
Top