3 ms·
0. Insure you have documented the steps/workflow to find the vulnerability and how it was exploited so tasked with fixing it can reproduce your results. This s
by techjuice 9y ago
0. Insure you have documented the steps/workflow to find the vulnerability and how it was exploited so tasked with fixing it can reproduce your results. This should be very detailed with pictures, tools used and results/expected results. If you can automate this then it is even better.
1. Check if the site has a bug bounty program, as results submitted there normally go directly to the security team or someone that can get the issue resolved.
2. If you are not able to find a bug bounty program, I would recommend contacting the site support or using the contact form on the site.
3. If that is unsuccessful, email/call the contact information on the website's WHOIS query page (whois domain.tld in terminal)
4. If that fails use twitter to send a DM to the sites social media contact.
5. If that fails make a public post to the twitter contact (e.g. @newcontact "Hi there, I found a pretty serious problem with your site contact me ASAP."