Better communication with website owners

Questions or suggestions about the platform
User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm
Better communication with website owners

Post by x1admin » Wed Feb 28, 2018 7:11 pm

Hi Folks,



We just had a case when one researcher continuously and systematically did not answer a website owner truly willing to fix the vulnerabilities, but was posting new submissions instead in the meanwhile (our emails remained ignored as well). Such behavior is definitely against OBB values of responsible and coordinated disclosure aimed to help website owners. This is an isolated case but we want to prevent any similar situations in the future.



Please:

Update your profiles and make sure you have an email AND some alternatives contacts there. Profiles without contact details my be suspended unless contacts added.
Respond to website owners as promptly as practical and reasonable. Abandoned reports (i.e. you keep silence over 45 days despite website owner’s requests for details) may be deleted or disclosed to the website owner before public disclosure. Otherwise it’s just unfair towards the website owners who cannot fix the vulnerabilities.



We really try to make things comfortable for everyone here and please follow these simple rules =)

secuninja
Posts:508
Joined:Fri Apr 28, 2017 2:34 pm

Re: Better communication with website owners

Post by secuninja » Thu Mar 01, 2018 6:19 am

Hey, why not installing a process in which the notified website owners can also rate researchers?
Add some kind of token to the notification email which can be used once the report is marked as patched or public disclosed.
Also add a button like "Researcher is unresponsive" to inform the admins when a owner has issues to get details.

User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm

Re: Better communication with website owners

Post by x1admin » Thu Mar 01, 2018 7:43 am

secuninja wrote:
Thu Mar 01, 2018 6:19 am
Hey, why not installing a process in which the notified website owners can also rate researchers?
Add some kind of token to the notification email which can be used once the report is marked as patched or public disclosed.
Also add a button like "Researcher is unresponsive" to inform the admins when a owner has issues to get details.
We implement researchers rating soon

secuninja
Posts:508
Joined:Fri Apr 28, 2017 2:34 pm

Re: Better communication with website owners

Post by secuninja » Thu Mar 01, 2018 8:24 am

awesome :)

RiceNinja248
Posts:16
Joined:Thu Oct 12, 2017 2:26 pm

Re: Better communication with website owners

Post by RiceNinja248 » Thu Mar 01, 2018 5:07 pm

secuninja wrote:
Thu Mar 01, 2018 6:19 am
Hey, why not installing a process in which the notified website owners can also rate researchers?
Add some kind of token to the notification email which can be used once the report is marked as patched or public disclosed.
Also add a button like "Researcher is unresponsive" to inform the admins when a owner has issues to get details.
Great idea! :)

kongwenbin
Posts:18
Joined:Sun Sep 24, 2017 4:30 am

Re: Better communication with website owners

Post by kongwenbin » Sat Mar 03, 2018 5:25 pm

Definitely a great idea ;)

vpq_wtf
Posts:118
Joined:Mon Apr 25, 2016 3:43 am

Re: Better communication with website owners

Post by vpq_wtf » Mon Mar 05, 2018 6:15 pm

Perhaps it's down to the fact that some website owners are ignorant and rude.

I have worked with various website owners in the past that have promised me a reward upon disclosure, when disclosure is issued, they proceed to ignore me.

Now, if one reported another vulnerability on their website through www.openbugbounty.org, why would one respond to them with details on the new vulnerability?

secuninja
Posts:508
Joined:Fri Apr 28, 2017 2:34 pm

Re: Better communication with website owners

Post by secuninja » Tue Mar 06, 2018 5:28 am

because we're (mostly) the good guys

ob1ob1ob1ob1ob1
Posts:2
Joined:Tue Apr 03, 2018 6:22 pm

Re: Better communication with website owners

Post by ob1ob1ob1ob1ob1 » Thu Apr 19, 2018 5:11 pm

I submitted a request regarding lack of contact from a researcher at https://www.openbugbounty.org/about/contacts/ and no one has returned our message. What additional steps are necessary?

secuninja
Posts:508
Joined:Fri Apr 28, 2017 2:34 pm

Re: Better communication with website owners

Post by secuninja » Thu Apr 19, 2018 7:33 pm

can you provide the report id?

Post Reply

Who is online

Users browsing this forum: No registered users and 2 guests