I need your advice on bug discovery and compensation

Bendayula

Newbie
Joined
Jan 7, 2019
Messages
1
Reaction score
0
I want to say this might be offtopic but I will appreciate your contribution. I detected a security bug on a popular POS software which enables me to login to the software without password. And it gives me full access to the software which ordinarily should not be and I should be limited to the department of the company I work for but now I can view, edit, create anything. Also logged in successfully in another company using same software. I'm thinking of reporting it to the software manufacturer but with compensation cos it's an highly sensitive issue with ability to run down any company using the software.
 
Don't do anything illegal with it.

You can either forget what you discovered, or tell them it.

Good companies have bug bounty programs, but I don't know if it's the case here...
 
I am 99% sure that if you will contact the right person in that company, you will get some kind of reward.
Note: It can be also a t-shirt :)
 
Report it. Earn yourself some good karma.
 
You could contact them asking if they would pay for [class of vulnerability you found] and go from there.

Otherwise, the expected thing to do is disclose it to the manufacturer and do a writeup 90 days later - which you can use for credibility on your CV etc.

Alternatively, there are companies and forums where vulnerabilities are bought - I'm not entirely sure of the legality of this.
 
Back
Top