hi, i’m daniel. i’m a 15-year-old with some programming experience and i do a little bug hunting in my free time. here’s the insane story of how I found a single bug that affected over half of all Fortune 500 companies:

  • Elvith Ma'for@feddit.org
    link
    fedilink
    English
    arrow-up
    38
    ·
    2 months ago

    I couldn’t help but find it amusing—they were now asking me to keep the report confidential, despite having initially dismissed it as out of scope.

    “Sorry, but per your own guidelines this is out of scope. Because of this, this bug is not part of the agreement and guidelines on Hackerone. You can find my full disclosure, that I wrote after your dismissal here: <Link>” /s

    • bjornsno@lemm.ee
      link
      fedilink
      English
      arrow-up
      5
      ·
      2 months ago

      I mean, that still allows zendesk to reply with “oh yeah that’s also why we’re not paying the bounty”

      • Elvith Ma'for@feddit.org
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 months ago

        Well, they did it anyways, so…

        Also this might work as an answer to “yeah, it’s a bug, but we won’t pay you”