27 ms·
I don’t think asking for money is the issue- it’s the overall handling of the situation on the researcher’s side. If you’re only trying to collect bounties, yo
by jackson1442 3y ago
I don’t think asking for money is the issue- it’s the overall handling of the situation on the researcher’s side.
If you’re only trying to collect bounties, you should go to a bug bounty website and work on sites that are explicitly soliciting bounties - that way you aren’t wasting your time finding vulnerabilities on sites that have no interest in paying out, and you can see which types of vulnerabilities are in- and out of scope.
On the other hand, I don’t think it’s particularly rude to shoot an email over explaining the vulnerability while at the same time requesting compensation. But gating information on the vulnerability behind a request for compensation is not appropriate.