Option to disclose vulnerability to webmaster

Questions or suggestions about the platform
Post Reply
MitRauch
Posts:8
Joined:Mon Feb 12, 2018 12:00 pm
Option to disclose vulnerability to webmaster

Post by MitRauch » Thu Feb 15, 2018 10:05 pm

Hello!

When reporting an incident we already got to choose, whether to post it publicly, without any technical details, or to post it secretly, with the technical details disclosed - another option, combining both would, be really nice.

I think many people would mistake an email from the website as SPAM and won't react. Maybe this could be changed, if we gave those people a possibility to verify or findings, by providing them with the actual PoC.

Shouldn't be to hard to implement. Additionaly to the public URL, with the technical details hidden, just generate a secret URL to be sent with the email notifying the website owner.

I'd really appreciate the implementation of this, since it could help eliminating thoughts about our reports being some kind of SPAM or blackmail.

User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm

Re: Option to disclose vulnerability to webmaster

Post by x1admin » Fri Feb 16, 2018 7:22 am

MitRauch wrote:
Thu Feb 15, 2018 10:05 pm
Hello!

When reporting an incident we already got to choose, whether to post it publicly, without any technical details, or to post it secretly, with the technical details disclosed - another option, combining both would, be really nice.

I think many people would mistake an email from the website as SPAM and won't react. Maybe this could be changed, if we gave those people a possibility to verify or findings, by providing them with the actual PoC.

Shouldn't be to hard to implement. Additionaly to the public URL, with the technical details hidden, just generate a secret URL to be sent with the email notifying the website owner.

I'd really appreciate the implementation of this, since it could help eliminating thoughts about our reports being some kind of SPAM or blackmail.
You can provide details after webmaster contacted with you
We can't send emails with any details or link to open details

Post Reply

Who is online

Users browsing this forum: No registered users and 2 guests