Page 1 of 1

How to post vulns not in the form?

Posted: Sat Mar 23, 2019 6:05 pm
by barf0x
Hi
I have made a non intrusive scan for ports on a website listed here and detected a suspicious 31337 port open, that tells me it might be a Remote Administration Tool/backdoor.
I cannot submit this in the form on the website here because I only see XSS, CSRF, Improper access control etc in the form.
Any ways to contact the owner through Openbugbounty to notify him of this finding and ask him a question about the suspicious port? This finding doesn't necessarily indicate malware till I can't get feedback from the owner so I would like to notify him.

Thanks!

Re: How to post vulns not in the form?

Posted: Sat Mar 23, 2019 8:30 pm
by GordSchramm
I would just find the email of the site owner and notify them that way.....trying not to make it look like spam or a phishing email.....

Regards,