Login Register
The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


How to not get in trouble as a bug bounty hunter? filter_list
Author
Message
How to not get in trouble as a bug bounty hunter? #1
Hi,

I have a question. On HackerOne you have a list of companies that will pay you if you find a vulnerability on their website, right? Like for example Facebook.

Let's say I'm a hacker and I start testing their website (try sql injection, xss, and you name it) now all of these tests I've done on their website are logged and my IP appears on these logs right?

So how do they know that I was testing their website for the bug bounty program, how do they differentiate me as a bug bounty hunter from those who have malicious intentions?

How do you make sure to not get into trouble as a bug bounty hunter?

Can someone with experience answer to this question?

Thanks a lot!
(This post was last modified: 08-25-2019, 10:05 PM by SneakyBit.)

Reply

RE: How to not get in trouble as a bug bounty hunter? #2
If you are eager to test your skills
Ping me on skype : panoldbiz

Reply

RE: How to not get in trouble as a bug bounty hunter? #3
I'm not a lawyer, but as long as you don't save any confidential information and you minimize damages it should help your case. You do need to be able to provide proof of concept and I'm sure they understand that. As soon as you start saving confidential information and causing damage, criminal intent becomes more obvious. I'd maintain that you want to preserve your anonymity, regardless of your intent.
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

Reply

RE: How to not get in trouble as a bug bounty hunter? #4
(08-26-2019, 12:52 AM)Oni Wrote: As soon as you start saving confidential information

"Viewing" confidential Information, has the same Impact- the difference being It's stored In one's memory and not on a device.

Be extremely careful with every move you make.
[Image: AD83g1A.png]

Reply

RE: How to not get in trouble as a bug bounty hunter? #5
Damn, well that's enough to keep me from doing this. Anyway if I do this then I will take your advice @Oni and try to remain anonymous. Thanks for the replies Wink

Reply

RE: How to not get in trouble as a bug bounty hunter? #6
There's a lot of trust in the bounty maintainer really... In my experience, as long as you take the first steps to report an exploit, and are following the engagement guidelines, they are very willing to work with you. It all depends on your intent really. I've even seen cases where researchers will step outside of the engagement scope, but still be rewarded cause it was clear that they weren't doing ti malicilously. Generally just make sure your payloads are POC not meant to cause damage. ie alert(1), math equations in sql injections, time based sql injections that don't return anything., etc.

Reply







Users browsing this thread: 1 Guest(s)