Hacker News new | past | comments | ask | show | jobs | submit login

I always love reading writeups of these vulnerabilities.

On a related note, I love that bug bounty programs are becoming more popular. Still too rare, but great. That said, the majority of companies out there still make reporting vulnerabilities tough. I've reported a number of vulnerabilities, and all but a few companies had no security@ email address nor a security contact under Contact Us. The tech/admin contact of the DNS record often does the trick, but doesn't always work.

Please, companies, make it easier for us to report security vulnerabilities!




The problem is that if someone finds a bug in say, PHP, the exploit could easily be worth 60-100x the $1500 you'd get paid when its fixed.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: