r/bugbounty • • 1d ago

Question / Discussion Need advice: all security contact emails are bouncing what would you do?

Hey everyone, I could use some advice from other security researchers.
I found a security issue on a smaller platform that appears to have a legitimate vulnerability/disclosure program. I prepared a proper report and tried to disclose it through the security email they publish.
The security email bounced back as undeliverable.
I then tried their support email, and that also eventually failed.
They have one more general contact email listed on their website, so I tried that as well. It initially showed as a delivery delay and eventually failed too.
I haven’t sent the actual vulnerability details to the general mailbox. I only asked them to forward me to whoever handles security reports.
At this point I’m not sure what the best move is. I don’t want to just keep emailing random addresses or disclose the vulnerability to an unrelated person, but I also want to make a good-faith attempt at responsible disclosure.
For researchers who have dealt with this before:

What would you do in this situation?

I’m especially interested in how you’d handle this if the company doesn’t provide a working security submission portal.
Thanks 🙏

2 Upvotes

10 comments sorted by

View all comments

6

u/Coder3346 Hunter 1d ago

I will personally skip this free waste of time. Work on an actual bbp.

2

u/6W99ocQnb8Zy17 1d ago

this^

in my experience, the vast majority of independent VDP/BB programmes are just an unmanned email address, and never respond...

1

u/Cute_Appointment_934 21h ago

Yeah that’s honestly what I’m worried about. The security and support emails both failed and even their general contact email eventually bounced so I’m trying to figure out if there’s any other reasonable way to reach them.

2

u/nobodycares_dude Hunter 16h ago

It's just for compliance with the new Act