3 ms·
Typically a company would post a contact channel for this type of stuff. The boilerplate is security@company.com, which is what my (small) startup does. Barrin
by snide 3y ago
Typically a company would post a contact channel for this type of stuff. The boilerplate is security@company.com, which is what my (small) startup does.
Barring that an email to the administrator through a contact form would work. If you're worried about how they will percieve this feedback, I'd start with a query before submitting the issue. "I noticed a potential security issue with your site. What is the best way to report it?".
- mtmail 3y agoAlso check for a https://securitytxt.org/ https://securitytxt.org/ file but it's rare.
- mtmail 3y ago> "I noticed a potential security issue with your site. What is the best way to report it?" It should come with more back-story because companies (security@ email address) receive quite a few of similar emails and many are borderline spam. I'm talking about security researchers telling us they found something, then when we reply asking for details there's silence. To the point where we sometimes not even answer any more. It's a sad state of security research where some are spamming 100s of companies.
- viraptor 3y ago> I noticed a potential security issue with your site. Please don't stop there! There's thousands of people who will try that hook, but if you try to reach out, you'll learn they claim insecure headers in http response and want bug bounty money for it whether you offer it or not. If you're sending the email, make a new section with all the technical details included immediately. Otherwise you risk going straight to the bin.