What Would You Do In This Situation?

Elliot305

BANNED
Joined
Jul 21, 2010
Messages
641
Reaction score
1,891
I've had some situations arise throughout the years and am wondering what people here in BHW would do. So without going into detail on each situation I've been in, I'll simply pose a question to you in a broad sense. My forte is exploiting online advertising systems/platforms. As I continue to find and successfully exploit new things, I grow a stronger belief in myself and abilities...so much so that I've actually considered offering my consulting services to these companies in order for them to "patch up" the weaknesses I've found.

So here is my question:

Would you NOT take advantage of a weakness you found in a system and instead, contact the company and submit a proposition to where they pay you a consulting fee in exchange for your services/expertise?

If you answered, Yes, you wouldn't take advantage and would try to work something out with the company directly, here is my next question: How about if you knew the exploit would make you a ton of cash very quickly and carried little to no risk?

So if you had these two options laying on a table, what would you do?:

Option 1: NOT exploiting it and offering your services to the company and maybe getting below $10k for your fee. (That's if they believe you in the first place, think your consultation will help them, and think a fee is justifiable for the info.)

Option 2: Go dark, take full advantage of it until it gets patched and make a lot of money with it ($100k+). Risks are only civil in nature but being that you went dark they wouldn't find you anyway.

Each time I come up against this scenario I never can justify going to the company because, frankly, it just isn't profitable enough for me to do so. I do however, envision myself becoming some sort of risk management consultant in the future and putting my skills to use in that capacity. But I really don't know how a company would put a value on something like that. It's weird because I almost needed to do Option 2 for years like I have to give me the experience and ego for me to even consider doing Option 1.

So what would you guys do in this type of situation?
 
Last edited by a moderator:
I'd take advantage of it to an extent then let them know after I'm satisfied with my earnings.
 
I have been though your methods nd all i can say is wow, you have exploited some really cool ways of making money so why not bank of them nd once we know its of no use just move on....
 
I'd take advantage of it to an extent then let them know after I'm satisfied with my earnings.

I doubt they would take kindly to the fact if I exploited them and then tried to consult for them. I would have to just find the weakness and not exploit it if I wanted to offer my services, etc...
 
Capitalism and Competition shouts this quote:

"In fact, to gull a fool seems to me an exploit worthy of a witty man."
Giacomo Casanova
 
I doubt they would take kindly to the fact if I exploited them and then tried to consult for them. I would have to just find the weakness and not exploit it if I wanted to offer my services, etc...

Raise your price and make them know how serious the exploit is. I mean, if you can make that much money with the exploit, I think they would value patching it more.
 
This is black hat world. Go dark imo... ;)
 
If option 2 is illegal that may put you behind bar then ONLY go with option 1. Else always go with option 2.

Watch 'Catch Me If You Can' movie. You may enjoy it!
 
Sounds like your question is just an overstated "should I make $2k or $100k?"

If you have enough avenues to work with, I say do both. Find the more profitable ones and abuse them until they're dry, and relegate the less profitable ones to resume stuffing material (assuming that's what you're going for when you say you want to eventually get into risk management consultancy).
 
Grow the balls and go for #2 - and don't forget to send me my consulting fee.
 
Why not do both?

The 1st will give you the reputation you're looking for, the 2nd will fill your pockets. For example:

Alter ego 1 - has a website that publicly lists every new exploit out there for companies A, B, C. First free of charge, thus forcing companies to act fast, because the information becomes available to a large group of people, who can then exploit them. Next, as a consultant, posting the explot only after it has been already fixed.

Alter ego 2 - banks on companies D, E, F.
 
I think youre focusing on this way too hard, seems like youve found an excellent money maker dont overthink things to the point you paralyze yourself.
 
Last edited:
I have good friends who do both options and have told me in detail about them.

My friend who tells the company the methods usually makes 5-10k per exploit.

My friend who exploits it like crazy became a millionaire this past year making over 600k alone from exploiting methods.

Obviously my 2nd friend probably is at more risk, but hey theirs a whole lotta money to be made!
 
I've often wrestled with this myself. I've hammered certain sites and networks in ways I'm sure they would've rather avoided, but as you said, at what cost? I might've made $25k-$50k from that method, and the company certainly wasn't going to pay that to me. What I was thinking about doing, although it's a bit of a risk as well, is keeping some sort of notes on my expeditions. It could be a bad idea as you'd essentially be incriminating yourself with the "diary", but there's point to it. If you were serious about becoming a consultant of sorts, the money wouldn't be made from 1 company alone, but rather by working with numerous companies. What I would do is look at charging a consulting fee to analyze a company's setup, and then go from there if action is needed.

Your diary then becomes your portfolio of sorts. I'm going to try and tiptoe around this, but here's an example. About a year ago, I rocked one of the biggest sites/networks on the net so hard they had to temp disable certain portions of their network. It wasn't anything that I could face any real legal issues from, but as in your case mentioned above, I could be held civilly liable I'm sure. I have at times revealed this and other exploits to prospective business partners where I felt it was warranted to show them I'm not just Joe Blow talking out of his ass. Because I can point to plenty of articles that detail what happened, and then show them the screen shots of things in action, it's a lot easier for them to see I know what I'm doing.

The reason I bring this up is you could do something similar but in a more public fashion. You continue right now just taking a wrecking ball to methods, build your "portfolio" then after a few years you compile all of your exploits into a very vague advertising campaign in which you introduce yourself as a "new" and "special" type of security consultant. There's a lot of ways to go about it from there, and I'm sure you're the last one I would need to try and explain that to, but if it were me I'd continue on the path you are now until you're comfortable with taking a little time off and setting yourself up. The reason I say to advertise yourself is, as I mentioned before you might not get the huge payout for closing a single door for them, but it will add to your reputation, and build help build credibility. The goal would be to manage a number of different companies. Then you can either charge a 1-time fee, or a monthly "monitoring" fee.

Sorry, sometimes I get to rambling in these things and cant' stop myself. To sum it all up though, I very much understand and think about the same thing, often. Have a great day, and happy hunting ;)
 
Back
Top