TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: How do I disclose bugs to a company without a bug bounty program?

11 点作者 scott_hardy将近 9 年前
I recently found bug on a large (publicly traded) company&#x27;s website that can lead to personal information exposure. The bug allows you to gain a user&#x27;s phone number and other personal information given only their email address.<p>What is the best way to contact this company and responsibly disclose these bug? They have no bug bounty program, I cannot find a dedicated email address for the developer team, and I am reluctant to email their customer support. Thanks in advance!

7 条评论

pmiller2将近 9 年前
As anonymously as possible, IMO.
评论 #12084412 未加载
MaulingMonkey将近 9 年前
&gt; I am reluctant to email their customer support.<p>If this reluctance is out of security concerns, you could always ask for the best contact method to report security vulnerabilities <i>without</i> disclosing the vulnerability to that email.<p>Plugging their website into <a href="https:&#x2F;&#x2F;whois.icann.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;whois.icann.org&#x2F;</a> may give you some alternative contacts if you just hate customer service.
yladiz将近 9 年前
Even though you&#x27;re reluctant to email their support, you can contact them without disclosing the specific issue and just ask for their security contact (or a person who is authorized to handle this kind of issue). An alternative is to contact them by phone number, if they have one readily available. Also what MaulingMonkey pointed out, you can see if the whois gives you any more contact info.
NameNickHN将近 9 年前
You could contact a well known security expert that does this kind of stuff professionally, unless you want to make a name for yourself.
flukus将近 9 年前
Post the exploit here. It will get to where it needs to go... eventually.
JSeymourATL将近 9 年前
Try emailing the CIO&#x2F;CTO direct. You can look up his address here &gt; <a href="https:&#x2F;&#x2F;emailhunter.co&#x2F;" rel="nofollow">https:&#x2F;&#x2F;emailhunter.co&#x2F;</a>
alexmingoia将近 9 年前
Don&#x27;t. Hold them for ransom. Why do you want to do charity work for for-profit businesses?