4 ms·
Fair point, my relucatance to stop was mainly due to companies usually disreguarding reports unless I have strong proof. Stopping short of the full scope would'
by mandatory 10y ago
Fair point, my relucatance to stop was mainly due to companies usually disreguarding reports unless I have strong proof. Stopping short of the full scope would've left it up to speculation as to the full amount of vulnerable domains.
It was my plan to delete the domains (or at least null route them so others couldn't take them over with more malicious intent). However my account was banned before I could do so.
- deleted 10y ago[deleted]
- tombrossman 10y agoHave you had any contact with DO's support or security team prior to this? You are correct that companies frequently ignore or downplay reports but it's nice to at least make that first attempt for each new find (per company). This is only ever done as a courtesy, I'm not saying you must or even that you should have here. Remember, it's just another nerd out there somewhere who receives your report. Sometimes they are super stoked to have it and will be very responsive. This can be more satisfying than a public disclosure without first contacting the company.
- Aeolun 10y agoThat turned out to indeed be the case after their first response :/ How would it have ended if you hadn't reached out to one of their security people after being banned? They'd have given you the traffic, locked your account, and congratulated themselves on a job well done?