Say you find an exploit... What do you do?

You find an exploit. What would you do? And you can get away with it


  • Total voters
    18
  • Poll closed .
Say you find an exploit and can exploit it for profit. and you know you can get away with it.

Would you exploit it for max profit? or would you report it to the company and hopefully have a nice reward?

:o
I would disclose the vulnerability responsibly by contacting the company and giving them reasonable time to fix the issue before making it public.

In any case, I wouldn’t exploit the bug directly. I could still benefit from it either through a bug bounty or by creating a video that explains the process for others to learn from (ofcourse, after the bug has been fixed, or the time has passed).
 
Its all about how likely are legal problems because of exploiting this expolit.

If there is no bounty program its possible that you wont get anything for reporting this exploit.
 
I would disclose the vulnerability responsibly by contacting the company and giving them reasonable time to fix the issue before making it public.

In any case, I wouldn’t exploit the bug directly. I could still benefit from it either through a bug bounty or by creating a video that explains the process for others to learn from (ofcourse, after the bug has been fixed, or the time has passed).

Its all about how likely are legal problems because of exploiting this expolit.

If there is no bounty program its possible that you wont get anything for reporting this exploit.

Tried searching for a bug bounty, but unfortunately there is none, so it's game on :D
 
@Gogol hey, I tried to do the right thing, man! :D
Have you tried reaching out to them directly? Many companies run private bounty programs, and they usually appreciate those kinds of tips. ;)
 
Have you tried reaching out to them directly? Many companies run private bounty programs, and they usually appreciate those kinds of tips. ;)
Thing is that I believe that management know about it, but they think it's not worth it for someone to exploit it, so they won't do anything about it, and if someone came and told them about it, their reply could be "yeah, we know about it, but it's not worth it to abuse it."

But I found a way to make it profitable... :D

Maybe BHW should consider opening a bug bounty program? :o
 
Thing is that I believe that management know about it, but they think it's not worth it for someone to exploit it, so they won't do anything about it, and if someone came and told them about it, their reply could be "yeah, we know about it, but it's not worth it to abuse it."
I don’t know, I personally think if I have the skill to detect such a vulnerability, may be I would do something constructive with the skill instead of ruining other people’s businesses. But that’s just me. :)
 
Depends on the company tbh. If it’s some greedy corp that’s already swimming in billions, I’d definitely be tempted. But honestly, most exploits get burned pretty fast, and you can get into serious trouble. Reporting it officially and getting a bounty — you sleep well, plus +100 karma for your resume. So yeah, it’s basically a choice: quick cash now or long-term reputation
 
I don’t know, I personally think if I have the skill to detect such a vulnerability, may be I would do something constructive with the skill instead of ruining other people’s businesses. But that’s just me. :)
Believe me, if it was some organization that helps humanity in some capacity, I WOULD NOT do it and simply report even if I get nothing
Unfortunately, that isn't the case.
It's like a "scamming a scammer" kind of things, if that makes sense

Depends on the company tbh. If it’s some greedy corp that’s already swimming in billions, I’d definitely be tempted. But honestly, most exploits get burned pretty fast, and you can get into serious trouble. Reporting it officially and getting a bounty — you sleep well, plus +100 karma for your resume. So yeah, it’s basically a choice: quick cash now or long-term reputation
Yup. Thought it out pretty well
 
If someone leaves an option to place my own links or leave contact details, that's enough of an exploit for me.
 
Back
Top