logoalt Hacker News

codexontoday at 3:35 AM1 replyview on HN

I reported some exploits on hackerone.

Most got dismissed.

One of them, a remotely triggerable DoS vector got downgraded in severity. I got a token payment from the company, and 7 years later, it is still not marked as resolved.

I doubt my situation is unique.


Replies

tptacektoday at 3:42 AM

Most bounty programs won't pay for DoS at all.

show 1 reply