4 ms·
No. The companies offering bug bounties have already done more than the bare minimum. Finding a vulnerability for a bug bounty requires actual work.
by scoot 3y ago
No. The companies offering bug bounties have already done more than the bare minimum. Finding a vulnerability for a bug bounty requires actual work.
- yieldcrv 3y agothis seems to be airing a frustration that has moved beyond accuracy in the process, companies offering bug bounties may have done the bare minimum at one point in time but every production push they do changes that, and potentially reintroduces simple scannable vulnerabilities.
- scoot 3y agoThat's fair. We get numerous reports from script kiddies reporting "vulnerabilities" that aren't, because they don't understand the tool that they're running, or the output that it produces, or why it isn't relevant. It's possible that they catch a known issue, but the reality is that the majority have no idea what they're doing.
- alaeddine001 3y agoWe did test it on Bug Bounty targets (see article) and found 2.5% of programs to suffer from at least one of these issues.
- alaeddine001 3y agohttps://blog.ostorlab.co/known_exploitable_vulnerabilities_catching_them_all.html https://blog.ostorlab.co/known_exploitable_vulnerabilities_c...