Every pen-tester and red teamer has a story of when they accidentically hacked into something they didn’t have permission to, thinking it belonged to the company/client. What’s yours?
34
12
4
110
Replying to @jeremiahg
Important lesson: if your company whitelabels a vendor solution, be sure to either exclude it from your bug bounty scope OR ensure your contract with the vendor allows your BB researchers to test it. Otherwise, you could be facilitating a CFAA violation.

Oct 1, 2021 · 8:30 PM UTC

1