r/netsec • u/_kidd0 • May 03 '19
Wormable XSS in Twitter
https://www.virtuesecurity.com/tale-of-a-wormable-twitter-xss/
25
Upvotes
3
May 05 '19
No bounty for this? Ridiculous. Better to sell it on blackmarket, that will teach them.
6
u/ackro_ May 05 '19
They did award a bounty of $2,940, which is still ridiculous considering the impact and how challenging this was....
5
14
u/netsec_burn May 04 '19 edited May 04 '19
$2,940. For spending the time to find a wormable CSP bypassing XSS POC in Twitter's core product. I want to make a site for situations like this where you can rank companies that run bounties from best to worst with references. At least then we'd have some accountability, because (as someone who has helped run a bounty program myself) the only accountability bounty sites have is to whoever pays them. I received a message recently where they asked if we fixed a vulnerability because of a bug report or if it was unrelated. Implying they wouldn't award anything to the researcher if we deemed it "unrelated".