Ask HN: Worth following up? Publicly facing root passwords on a Fortune 100
Essentially, I recently found a publicly facing document which detailed ALL of the root passwords for a Fortune 100 company. (Amongst other things, it was an open directory which also included all of the staff VPN passwords, and other sensitive information including SQL backups). I immediately reported this issue to them. I was told they would get back to me, and after reporting the issue I have sent multiple followup emails and have been selectively ignored. (I stumbled upon the root passwords completely by accident while looking around Google for information relating to an unrelated company). They have now removed the documents in question, (though they are still cached by Google). Should I let this go? I'm not sure whether it's worth pursuing. I don't want recognition, or hush money. I would have been content with a thank you, and I would have called it a day. Oh, and if it is relevant I sent my first email on January 23rd.
10 comments
[ 3.1 ms ] story [ 24.3 ms ] threadI considered just emailing the CEO and being all "Hey, thought you should be aware that I've sent multiple emails and just wanted to ensure you are informed"
Hi JungleCats,
Thank you for your participation in the PayPal Bug Bounty program.
While we continue to review each vulnerability we receive on a case-by-case basis, we have determined that this bug is not eligible for payment based on the fact the website is in the process of being decommissioned and will be shut down in the near future.
Thank you, PayPal Security Team
yawn
You've done a Good Thing, but like many good things, it will most likely go unrewarded.
For an enormous corp to take down a file in a couple of weeks is thanks and recognition enough I think.
I never heard anything back, but a month or so later, it was fixed.
I'm glad it was some years ago. These days, I think I'd fear that their legal team would seek to have me criminally charged and/or bankrupted, regardless. (Don't look at the password caching; that's "hacking".)
I guess you did a good thing. In this day and age, though, I almost wish they were named, as such behavior represents an extreme form of negligence. (I am not advising you to reveal them, though. See, for example, my previous paragraph.)