I found a flaw, should I report it???

Don't ask him for the list in exchange for the flaw, it will come across bad and why would he want to give you his customer list anyway? Instead just take the list and report the flaw anonymously.
 
Eh, you don't do anything bad imho

You actually help the webmaster by telling him that he has problems and you offer yourself to help

What idiot would sue someone who tries to help him ? ( if yes, for what and probably wasting time/loosing )

Lmao ;)

Well I am assuming the op is from the States.
 
Hey guys.

Yes I am from the states and no, I did not use a proxy. It's my real IP on the server. I plan to be finished by Monday as they are out of the office on the weekends.

Someone brought up a good point about then looking for spam after I made them aware of the flaw and then linking the two together. Having said that, I may not report it. The flaw is there but based on the type of customer they serve, it will most likely never be uncovered. I just happen to know enough about their company that I was able to tweak things into my favor.

As far as me fixing it, I would not have a clue how to do it. It's way above my head and most likely is a flaw in the database program they are using.

If I do have it patched, then that will cut off all future access to this list. Over the period of one-year, each contact will generate around $2 sales (average). With thousands in the system, that is a huge chunk of change to leave on the table.
 
Either don't report it and keep quiet keep the contacts up to date or copy down the contacts you can now report it and use the list for your needs or sell it (let me know more about it as I am always looking for good contact lists)
 
Rather than semi-hacking the site, I would tell the owners of the issue, you may or may not be rewarded but in the long run you would be sleeping pretty good at night.'

I came to know that making money legally is more simple compare to doing illegal stuff.

BassTrackerBoats you are loved!
 
So, is it OK (legally) for me to tell them that in exchange for their membership list that I will reveal the flaw?

I am not a lawyer and you should probably talk to one before saying anything because you have likely already committed a crime and corporations have a legal obligation to aggressively defend there businesses. Bad press can cause huge financial damages in many cases and if you cause those damages you could get into a world of trouble.
Giving them the info is good if done properly with the right legal protections in place otherwise do it anonymously so they can't over-react like many corporations do. Otherwise forget about it... don't steal the data, don't talk about it. Don't make a target of yourself. Making demands (viewed as blackmail-like or cyber-terrorism-like threats) is where it potentially turns into a crime. Negotiating your reward upfront is a very bad idea. Stealing the data is also likely to be a crime in most countries and one where the courts and the corporations are hell bent on making examples of people.

A lawyer could make sure you don't open yourself up to prosecution or litigation and possibly negotiate a "no conditions except release of liability" for disclosing the security threat and could probably do it in a way that the company might issue a press release stating that you reported and protected the company from a severe security loophole... such press releases can make a career for you in web security firms if you are interested in that as a career.

In short... do nothing and forget all about it... or pay $500 to a lawyer to do it safely and in a way that benefits your resume.

Those are your best options.

If you approach the company yourself, don't be surprised if it blows up in your face... I'd give it 50/50 odds on doing that.

Ted
 
Back
Top