Advice on notifications

Questions or suggestions about the platform
Post Reply
AS_BBC
Posts:1
Joined:Tue Mar 07, 2017 7:51 am
Advice on notifications

Post by AS_BBC » Wed May 16, 2018 4:06 pm

Hiya

We've received an email telling us our subscription is expiring. But i'm unclear how we go about renewing it.

We currently receive email notifications for vulnerabilities submitted for our domain (we signed up to these back when the site was still called xssposed).

Can you confirm you are effectively ending the old model completely and going forwards the only way to get email notifications of vulnerabilities posted on your site is via our security.txt file? And we have to post a link to a specific open bug bounty account (that itself has to be linked to a twitter account due to your sign in model) in that security.txt. We are working on a direct notification procedure for security.txt and wouldn't be able to link this to a specific 3rd party platform. We would still be interested in email notifications if that is possible - but you don't seem to offer alternative routes for verification. If not - fair enough - I guess we will part company.

Many thanks for your help with this and for the previous notifications,

User avatar
x1admin
Site Admin
Posts:3102
Joined:Sun Nov 15, 2015 7:04 pm

Re: Advice on notifications

Post by x1admin » Wed May 16, 2018 5:01 pm

AS_BBC wrote:
Wed May 16, 2018 4:06 pm
Hiya

We've received an email telling us our subscription is expiring. But i'm unclear how we go about renewing it.

We currently receive email notifications for vulnerabilities submitted for our domain (we signed up to these back when the site was still called xssposed).

Can you confirm you are effectively ending the old model completely and going forwards the only way to get email notifications of vulnerabilities posted on your site is via our security.txt file? And we have to post a link to a specific open bug bounty account (that itself has to be linked to a twitter account due to your sign in model) in that security.txt. We are working on a direct notification procedure for security.txt and wouldn't be able to link this to a specific 3rd party platform. We would still be interested in email notifications if that is possible - but you don't seem to offer alternative routes for verification. If not - fair enough - I guess we will part company.

Many thanks for your help with this and for the previous notifications,
We discontinued support old notification model. Security.txt it's fast and easy method to confirm website ownership, all you need it's just add one string to your security.txt file. You can delete this string after verification.

Post Reply

Who is online

Users browsing this forum: No registered users and 2 guests