TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: How do I report vulnerabilities and bugs?

5 点作者 kevindeasis超过 3 年前
Very frequently I notice bugs and vulnerabilities to different websites &#x2F; products &#x2F; saas.<p>Some of them are minor, and some are definitely very severe. From famous startups to really big companies.<p>What would &#x2F; can you guys do ethically &amp; legally? I did find some horror stories in the past about people reporting vulnerabilities<p>Is there a way to ethically make a decent living from this? IE: consulting, employed, self-employed, etc?<p>It seems most of it is not crystal clear and certain as other career tracks. IE: if i wanted to switch careers to be a PM or sales, etc and i wanted to be an insta millionaire, there&#x27;s a well documented path for that

3 条评论

toast0超过 3 年前
&gt; I used to report these things, but half of the time, they usually don&#x27;t get it fixed<p>You&#x27;ve definitely got to prioritize here. Minor things, send once and move on for the most part. Some things really don&#x27;t warrant a response; if you tell me I&#x27;m exposing TLS 1.0 and the world is going to end, I&#x27;m going to ignore you because I have <i>reasons</i> to run TLS 1.0 and too many poor quality reports; same thing if I expose the version of Apache I&#x27;m running --- I don&#x27;t care if some checklist says I shouldn&#x27;t do it.<p>If you tell me such and such link is XSS (and it actually is), I&#x27;ll try to fix it ASAP and hopefully let you know, but sometimes communication falls through the cracks; anyway, you&#x27;ll be able to see it&#x27;s fixed. For real issues, it&#x27;s probably worth trying to follow up after a couple weeks. If they have a public security program, use that, otherwise customer service and whois contacts, maybe send a paper mail to the CEO. Look at how project zero reports on communication with the vulnerabilities they report, and try to emulate that. Obviously, they&#x27;ve got a lot of industry contacts and their team is well known, so they&#x27;ll have an easier time getting in touch with people than you.<p>&gt; Is there a way to ethically make a decent living from this? IE: consulting, employed, self-employed, etc?<p>Depends on where you live. If you live in a low cost country, you might be able to make enough from bug bounties. Otherwise, you&#x27;re going to need to figure out how to get hired, either as a general researcher doing reports on the world at large (like you&#x27;re currently doing), or as a consultant for specific clients identified in advance. While you might get lucky and turn some reports into a business relationship, it&#x27;s tricky to do that without looking like you&#x27;re begging for bounties <a href="https:&#x2F;&#x2F;www.troyhunt.com&#x2F;beg-bounties&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.troyhunt.com&#x2F;beg-bounties&#x2F;</a><p>Apply to existing security consulting companies and see how that goes.
评论 #29562924 未加载
Dicey84超过 3 年前
I&#x27;ve only once reported what I perceived as a vulnerability in the Signal Android app.<p>Three months on since the report, the issue still exists and not even an acknowledgement of the report.
t-ubukata超过 3 年前
Companies often ignore bugs and vulnerabilities report. How about reporting to their country&#x27;s CERT?