Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is my favorite sort of email that we get about once a month in various forms... their title at the end is hilarious.

---

Subject: Found a security vulnerability on your website.

Hi Team, I am Harris, a security researcher, and I have found a security vulnerability in your website outside a bug bounty program.

I can disclose all the vulnerabilities found and their proper fixes too, to make your website more secure.

Companies I helped have always been generous and helped me back with rewards in amounts they think are appropriate to the issues I have found. If you appreciate my help, I'd be happy to receive a bonus payment via PayPal, Bitcoin, Payoneer, or Bank Transfer.

Waiting for a positive response from your end.

Thanks and Regards,

Harris A

Certified Ethical Hacker



On the off chance you entertain these individuals, it's usually something really dull an automated scanner picked up.


What happens if you don't pay? Or do they expect you to pay up front for essentially a pig in a poke?


The last one I engaged with only mentioned payment after the fact (along with wanting me to hire them to do a full pentest).

I just ignored them and that was it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: