PSA: If you go out of scope on a bug bounty program you might be breaking the law (standard IANAL disclaimer applies obv). I know it sucks to get an informative, N/A, or just no bounty, but compared to being prosecuted it's not so bad.
2
5
50
Yes, hard to know if it’s a researcher who overstepped their scope or a criminal trying to double-dip (exploit the vuln, then get paid to report it).
Jul 11, 2019 · 3:08 PM UTC

