What to do if you find a security vulnerability in mobile application?

nikhil79

Junior Member
Joined
Aug 5, 2011
Messages
104
Reaction score
27
So there's an android application with over a million downloads and it has a security vulnerability by which you can login to any user's account and make changes in their account, get there email id's, alternate contact numbers, physical address, etc. There is no debit card or credit card details but I can activate some points which will cause monetary loss to the user.

My question is how can I benefit this without getting into any legal actions or getting into any problem.
 
Report it to the developers and hope they will reward you with some cash.
 
Report it to the developers and hope they will reward you with some cash.

I am also thinking that contacting the developers is the best option.
 
Get every single user's email first and then contact the developers. Trust me, 9 times out of 10, they will just thank you for it, but won't give you any money or maybe too little. But if you have a super targeted list of 1 million emails, it's worth at least 7 figures if you know what to do with it of course. Nobody will know if you play it safe and don't spam the users too hard.
 
Last edited:
Get every single user's email first and then contact the developers. Trust me, 9 times out of 10, they will just thank you for it, but won't give you any money or maybe too little. But if you have a super targeted list of 1 million emails, it's worth at least 7 figures if you know what to do with it of course. Nobody will know if you play it safe and don't spam the users too hard.

There's a catch in getting the email ids that I need to have a mobile number to login the application and from there all the information can be retrieved. So getting a million numbers to get million email address won't be possible. Also email-ids won't be targeted.

And should i contact them with my personal email id or create a fake one? As it is a huge corporation with multiple business across the world so being a bit paranoid about it.
 
create fake email and recive payment in bitcoin if you plan contact them
 
There's a catch in getting the email ids that I need to have a mobile number to login the application and from there all the information can be retrieved. So getting a million numbers to get million email address won't be possible. Also email-ids won't be targeted.

And should i contact them with my personal email id or create a fake one? As it is a huge corporation with multiple business across the world so being a bit paranoid about it.

Can't you use the same number to login multiple times and get different email addresses? By targeted, I meant that all emails will have something in common, which is the interest in the kind of app/game you are using. For example, if you found a vulnerability in a chess game and got 1 million chess players' emails, then you can sell them anything related to chess and have a high CR, because they are targeted - if they didn't like the app/game or found it useful, they wouldn't have installed it in the first place. When you contact them, create a fake one and don't use your real name just in case.
 
Anyone else have any other thoughts?
 
Anyone else have any other thoughts?

When you report it to the developers you can try to make up a story about you being a freelancer pentester and if you can get a reward for that vulnerability.
 
Contact the developers. Do the right thing!
 
Back
Top