"disclosed by researcher"

Questions or suggestions about the platform
Post Reply
secuninja
Posts:508
Joined:Fri Apr 28, 2017 2:34 pm
"disclosed by researcher"

Post by secuninja » Thu Nov 02, 2017 7:42 pm

dear team,

as the disclosure policy changed few weeks ago and researcher cannot disclose on their own anymore the sentence "Vulnerability details disclosed by researcher" doesn't make sense any more? maybe "Disclosed according to OBB policies" or so would be more... you know adequate?

User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm

Re: "disclosed by researcher"

Post by x1admin » Fri Nov 03, 2017 6:03 am

secuninja wrote:
Thu Nov 02, 2017 7:42 pm
dear team,

as the disclosure policy changed few weeks ago and researcher cannot disclose on their own anymore the sentence "Vulnerability details disclosed by researcher" doesn't make sense any more? maybe "Disclosed according to OBB policies" or so would be more... you know adequate?
It’s a good point, however it’s still the researcher, and only the researcher, who can decide when to disclose. We just set a minimum to protect website owners, but everything else is in the researcher’s hands.

Any suggestions are welcome.

DrStache_
Posts:20
Joined:Sun Jul 31, 2016 2:56 pm

Re: "disclosed by researcher"

Post by DrStache_ » Mon Nov 13, 2017 6:43 pm

Hi,

Even if the report is patched, that's not possible to disclose it before the minimum time.
eg : /reports/360847 and /reports/363614/ (around 20 days, after the report date)

User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm

Re: "disclosed by researcher"

Post by x1admin » Tue Nov 14, 2017 7:03 am

DrStache_ wrote:
Mon Nov 13, 2017 6:43 pm
Hi,

Even if the report is patched, that's not possible to disclose it before the minimum time.
eg : /reports/360847 and /reports/363614/ (around 20 days, after the report date)

Open Bug Bounty submissions can now be disclosed on public in 90 days since submission to give to a website owner all reasonable possibilities to patch the vulnerability without putting its users at any risk. If the vulnerability is patched, this period is reduced to 30 days.

DrStache_
Posts:20
Joined:Sun Jul 31, 2016 2:56 pm

Re: "disclosed by researcher"

Post by DrStache_ » Tue Nov 14, 2017 6:58 pm

Thank you for the precision !

Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest