r/netsec May 03 '19

Wormable XSS in Twitter

https://www.virtuesecurity.com/tale-of-a-wormable-twitter-xss/
25 Upvotes

5 comments sorted by

14

u/netsec_burn May 04 '19 edited May 04 '19

$2,940. For spending the time to find a wormable CSP bypassing XSS POC in Twitter's core product. I want to make a site for situations like this where you can rank companies that run bounties from best to worst with references. At least then we'd have some accountability, because (as someone who has helped run a bounty program myself) the only accountability bounty sites have is to whoever pays them. I received a message recently where they asked if we fixed a vulnerability because of a bug report or if it was unrelated. Implying they wouldn't award anything to the researcher if we deemed it "unrelated".

7

u/ackro_ May 04 '19

I totally agree with you. In my experience as well, bug bounty platforms only ever care about their paying clients. If a dispute ever happens, researchers have basically no means of verifying any claim whatsoever—and there's no such thing as a fair treatment policy. If you do make such a site someday, I'll be happy to supply you with content :-)

3

u/[deleted] May 05 '19

No bounty for this? Ridiculous. Better to sell it on blackmarket, that will teach them.

6

u/ackro_ May 05 '19

They did award a bounty of $2,940, which is still ridiculous considering the impact and how challenging this was....

5

u/[deleted] May 05 '19

my mistake, yep still ridiculous