3 ms·
First thing is to see if the company has a bug bounty/responsible disclosure programming. If so make sure that what you have done falls under said program. Othe
by posnet 12y ago
First thing is to see if the company has a bug bounty/responsible disclosure programming. If so make sure that what you have done falls under said program. Otherwise it is not worth the risk to you. If you still feel motivated to do so, let them know through anonymous channels or contact a well know security researcher who will be less of a target if said company decides to take action.
- pitchit 12y agoI'll second this. If they have any sort of security program, go ahead and report it to them. Otherwise, it is a bit more risky. Personally, when this has happened to me in the past, I just send an anonymous email (over tor etc) to security@example.com and leave it at that.