Here is the email by yandex security team:
The above is an email by Yandex security team and according to them the vulnerability was reported before. However, speaking from my experience i haven't seen any researcher getting payed for reporting a vulnerability inside yandex.
Here are some tweets from some security experts, who have Participated in yandex bug bounty program and in most of the cases they are unable to reporduce the bug and in some cases they did not accept HTML injection and XSS as a security vulnerabilities:
Is yandex bounty program worth the time?, Decide for yourself.
You might also like: Make Money Online By Reporting Bug Bounties
No comments:
Post a Comment