3 ms·
it isn't simple request flooding, it is application level resource exhaustion
by codexon 2mo ago
it isn't simple request flooding, it is application level resource exhaustion
- tptacek 2mo agoYeah, I figured that's what you meant, and most bounty programs won't pay out for stuff like that. Every application has those bugs; on a software pentest, we'd sev:lo them.
- EraYaN 2mo agoSome of them can have 1 rpi take down a full 100 node cluster, so sure sev:lo but the cyber insurance often want them fixed anyway. But it will probably take it happening before C-suite decides that 0 revenue is a problem.
- nicce 2mo ago> Every application has those bugs; on a software pentest, we'd sev:lo them. Every application has a bug that can bring the whole application down for every user without owning a botnet? That comes often with a significant business cost, if someone exploits it. Many companies take them seriously. I have reported many as high and business has agreed. Not with HackerOne thought. If there is a bug where someone can make your whole product down with a single laptop isn't really something you can just ignore.
- tptacek 2mo agoYou can report a self-XSS sev:hi (and bounty hunters do) and get many orgs to take them seriously, because they don't have serious security practices. But DoS is generally sev:lo.
- nicce 2mo ago> You can report a self-XSS sev:hi (and bounty hunters do) and get many orgs to take them seriously, because they don't have serious security practices. Which can be definitely high, if it can be triggered by giving specific URL, for example. I think there is too much generalization happening here.