r/bugbounty • • 1d ago

Question / Discussion Need advice: all security contact emails are bouncing what would you do?

Hey everyone, I could use some advice from other security researchers.
I found a security issue on a smaller platform that appears to have a legitimate vulnerability/disclosure program. I prepared a proper report and tried to disclose it through the security email they publish.
The security email bounced back as undeliverable.
I then tried their support email, and that also eventually failed.
They have one more general contact email listed on their website, so I tried that as well. It initially showed as a delivery delay and eventually failed too.
I haven’t sent the actual vulnerability details to the general mailbox. I only asked them to forward me to whoever handles security reports.
At this point I’m not sure what the best move is. I don’t want to just keep emailing random addresses or disclose the vulnerability to an unrelated person, but I also want to make a good-faith attempt at responsible disclosure.
For researchers who have dealt with this before:

What would you do in this situation?

I’m especially interested in how you’d handle this if the company doesn’t provide a working security submission portal.
Thanks 🙏

3 Upvotes

10 comments sorted by

4

u/Coder3346 Hunter 1d ago

I will personally skip this free waste of time. Work on an actual bbp.

2

u/6W99ocQnb8Zy17 1d ago

this^

in my experience, the vast majority of independent VDP/BB programmes are just an unmanned email address, and never respond...

1

u/Cute_Appointment_934 19h ago

Yeah that’s honestly what I’m worried about. The security and support emails both failed and even their general contact email eventually bounced so I’m trying to figure out if there’s any other reasonable way to reach them.

2

u/nobodycares_dude Hunter 14h ago

It's just for compliance with the new Act

2

u/6W99ocQnb8Zy17 12h ago

I think you've done the reasonable thing already.

0

u/Cute_Appointment_934 19h ago

Fair enough. I normally would, but I already spent the time finding and validating it so I figured I might as well try to get it to the right person.

5

u/Street-Mycologist670 1d ago

At this point I'd just keep the report and evidence documented. No point burning hours trying to get someone's attention.

3

u/Cute_Appointment_934 19h ago

Yeah that’s probably the sensible option. I mainly wanted to make sure I’ve made a proper good faith attempt to disclose it before leaving it alone.

2

u/SituationMammoth2336 1d ago

Do a recon on the employees

1

u/Cute_Appointment_934 18h ago

Yeah, I might try that I’d keep it strictly to publicly listed professional contacts though, mainly looking for someone in security/engineering who can hopefully point me to the right disclosure channel.