5 ms·
We get a bunch of these - to be fair to them as mentioned in the article 99% are small setting tweaks we’ve overlooked. I always find it awkward replying to th
by TomGullen 5y ago
We get a bunch of these - to be fair to them as mentioned in the article 99% are small setting tweaks we’ve overlooked. I always find it awkward replying to these sorts of reports, usually I go with:
“Thanks for your report, we’ve updated the settings. We don’t have an official bounty program but we do sometimes offer them if the issue is severe enough. On this occasion it is not”
And that seems to work fine. For ones a little more involved we’ve paid out $50 a few times which they seem happy with and we’re generally ok to pay.
These setting tweaks are a source of spam, if you fix them you stop getting the emails.
I don’t have a problem with them generally but like Troy mentions the language they use can be quite manipulative and plays on your virtuous characteristics - short concise firm replies is what’s required and then ignore if they reply with beginning.
- dotancohen 5y agoYou might want to consider a "special thanks" page with the names of "white hat security researchers" who have pointed out issues. Public recognition costs you very little but for some of them it could be a significant career-building step, worth more than a few dollars or dinars.
- TomGullen 5y agoThat's a great idea
- ALittleLight 5y agoBut why would you want to build the career of someone who just scans websites with automated tools reporting vulnerabilities?
- Forbo 5y agoEverybody had to start somewhere. Yesterday's skids are today's legit researchers. If this is something they actually want to pursue, it could make a world of difference.
- mooman219 5y agoI don't think "someone who just scans websites with automated tools reporting vulnerabilities" is inherently a bad thing. At worst you get a free invocation of a tool you didn't know existed, at best you start a dialog and integrate the tool in your automated testing.
- ALittleLight 5y agoNo, I think at worst you waste your time and attention reading reports of benign issues from the invocation of an automated tool that you didn't care to execute. I think this is probably the worst, and median case. Maybe there is a way this could be useful. "I'm a security researcher. I ran this tool on your site which found these vulnerabilities. Here's why I think these vulnerabilities may be meaningful, even if they are first seem not to be" is, I think, a nice contribution and, if you make a change based on those suggestions, that merits some kind of credit. That's not really what is discussed in the article though.
- 908B64B197 5y agoSilicon Valley was built on "paying it forward". Everyone, no matter their skill level, should put 5% of their times toward mentoring and encouraging people to grow and build more. Someone scanning websites and checking for vulnerability is probably a student curious about security. Nothing wrong with a tap on the back and a free acknowledgment.
- ALittleLight 5y agoThe article makes it clear this person is behaving obnoxiously in a borderline threatening way. Why would you reward and encourage that behavior? They aren't a student, it's some guy running a script to scan for vulnerabilities and then beg for bounties.
- 908B64B197 5y ago> They aren't a student, it's some guy running a script to scan for vulnerabilities and then beg for bounties. Yeah, in this case it's pretty obviously scammers following a script from a foreign call-center. But I mean getting a legitimate student pointing out what he thinks are security flaws (and not begging).
- dotancohen 5y ago> But why would you want to build the career of someone who just scans websites with automated tools reporting vulnerabilities? You wouldn't believe that things that I'd done preceding my career. And such recognition might motivate him to take the next real steps. Not to mention that, if as a result of his scan a security improvement is made, then he did provide real value.
- DoreenMichele 5y agoThanks for your report, we’ve updated the settings. We don’t have an official bounty program but we do sometimes offer them if the issue is severe enough. On this occasion it is not” And that seems to work fine. For ones a little more involved we’ve paid out $50 a few times which they seem happy with and we’re generally ok to pay. This seems like an extremely reasonable approach.
- bawolff 5y agoThat's assuming the settings tweaks are even correct. I've seen plenty of these types of things where the suggested change is incorrect or otherwise not a mere oversight but actively a bad idea.
- igetspam 5y agoI've received them unsolicited in batches. I think there are training camps that show people how to this (spot debatable configs that I may chosen intentionally) and ask for money. Haven't seen anything exploitable.
- ratww 5y agoIt's often scanned, too. We have a small honeypot in our Wordpress blog that scanners assume is a vulnerability. Often I see email coming minutes after a certain file is accessed. Whenever we ask for details or true reproductions to the issue, they're unable to provide.
- toast0 5y agoYeah, I used to regularly get these reports when I ran a popular website. Sometimes (rarely), there was a glimmer of usefulness, but often it was just people telling us to turn off say TLS 1.0 or SSL 3; which would be nice... but we had to support clients that couldn't do better and modern clients won't use those anyway (or at least support the anti-fallback fake cipher, in cases where that helps). For things that only supported modern clients, we had better configs, but then those weren't www, so people didn't tend to test them.
- robryan 5y agoInteresting, the ones we have got are always after much larger figures. Some will link a hackerone or similar with a more serious version of what they are reporting to us that was reported to a billion dollar company to try and ground the value of their report.