4 ms·
Good point. The problem I know of is a bit different, in that it is a direct and immediate server crash. It's not a denial of service by making the cluster sl
by Max-Ganz-II 2y ago
Good point.
The problem I know of is a bit different, in that it is a direct and immediate server crash. It's not a denial of service by making the cluster slow. It's run-query, crash-server.
You are right of course that any normal user can issue crazy queries which hog resources, and hammer performance.
- orf 2y agoI would just reach out to AWS directly: why go through hacker one? They have a direct email and are responsive. If the issue meets their criteria then you get a payout.
- Max-Ganz-II 2y agoI Googled for AWS bug bounty programs. I found nothing. Do you have a URL of any kind, for more information about this, including contacts?
- TheDong 2y agohttps://aws.amazon.com/security/vulnerability-reporting/ https://aws.amazon.com/security/vulnerability-reporting/ I wouldn’t expect a bounty for something like this, but I believe the above is the correct avenue for reporting it.
- orf 2y agoaws-security@amazon.com - it’s very clearly the first result when you search “AWS security report”.