4 ms·
In my experience, most of these are just low-level extortion attempts where they run a point-and-click vulnerability scan and ask for money to see the results.
by jamieweb 8y ago
In my experience, most of these are just low-level extortion attempts where they run a point-and-click vulnerability scan and ask for money to see the results.
Before I had a bounty program I'd politely reply asking for information on the vulnerability, but now I do have a bounty program so I just point them there.
If the issue turns out to be real and you want to reward them, be very careful paying them directly, as often they seem to want Google-level bounty values even though you might only be a small business.