Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It was enough for Orange. But think about demand elasticity. Perhaps there are 100 other Oranges for whom the bounty was not enough.

Clearly the bounty was not enough for the mystery attacker / researcher / hacker / whatever that Orange discovered exploiting the same hole.



From Reginaldo's post it appears that it was another bug bounty guy who was the mystery attacker.


I personally find it a little difficult to believe that this was a security researcher. Exploiting a vulnerability (against the rules of engagement), _and_ uploading a web shell?

Seems more likely that Facebook wasn't thrilled that Orange included the details of an existing, unknown Facebook compromise in his write-up.


that's understandable




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: