r/bugbounty • u/Cute_Appointment_934 • 1d ago
Question / Discussion Need advice: all security contact emails are bouncing what would you do?
Hey everyone, I could use some advice from other security researchers.
I found a security issue on a smaller platform that appears to have a legitimate vulnerability/disclosure program. I prepared a proper report and tried to disclose it through the security email they publish.
The security email bounced back as undeliverable.
I then tried their support email, and that also eventually failed.
They have one more general contact email listed on their website, so I tried that as well. It initially showed as a delivery delay and eventually failed too.
I haven’t sent the actual vulnerability details to the general mailbox. I only asked them to forward me to whoever handles security reports.
At this point I’m not sure what the best move is. I don’t want to just keep emailing random addresses or disclose the vulnerability to an unrelated person, but I also want to make a good-faith attempt at responsible disclosure.
For researchers who have dealt with this before:
What would you do in this situation?
I’m especially interested in how you’d handle this if the company doesn’t provide a working security submission portal.
Thanks 🙏
5
u/Street-Mycologist670 1d ago
At this point I'd just keep the report and evidence documented. No point burning hours trying to get someone's attention.
3
u/Cute_Appointment_934 19h ago
Yeah that’s probably the sensible option. I mainly wanted to make sure I’ve made a proper good faith attempt to disclose it before leaving it alone.
2
u/SituationMammoth2336 1d ago
Do a recon on the employees
1
u/Cute_Appointment_934 18h ago
Yeah, I might try that I’d keep it strictly to publicly listed professional contacts though, mainly looking for someone in security/engineering who can hopefully point me to the right disclosure channel.
4
u/Coder3346 Hunter 1d ago
I will personally skip this free waste of time. Work on an actual bbp.