Skip to content

Comment on What to do after discovering SQL Injection vulnerability in random websites?

Comments

You can email the owner with a few tips to fix the issue. You can even offer to do a deeper inspection for some fee.

That might be interpreted as extortion. OP read up on responsible disclosure.

That's why I was careful to say that you should offer tips to fix the issue, not ask for money to do so. As for the second part (offering to do a security audit), I don't see how that's any different from cold-emailing someone with a proposal to redesign their site.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.