Full Disclosure mailing list archives
Re: PayPal.com XSS Vulnerability
From: Jeffrey Walton <noloader () gmail com>
Date: Wed, 29 May 2013 01:35:29 -0400
On Fri, May 24, 2013 at 12:38 PM, Robert Kugler <robert.kugler10 () gmail com> wrote:
Hello all! I'm Robert Kugler a 17 years old German student who's interested in securing computer systems. I would like to warn you that PayPal.com is vulnerable to a Cross-Site Scripting vulnerability! PayPal Inc. is running a bug bounty program for professional security researchers. ... Unfortunately PayPal disqualified me from receiving any bounty payment because of being 17 years old... ... I don’t want to allege PayPal a kind of bug bounty cost saving, but it’s not the best idea when you're interested in motivated security researchers...
Fortunately Microsoft and Firefox took a more reasonable positions for the bugs you discovered with their products. PCWorld and MSN picked up the story: http://www.pcworld.com/article/2039940/paypal-denies-teenager-reward-for-finding-website-bug.html and http://now.msn.com/paypal-denies-reward-to-robert-kugler-teen-who-found-bug-in-code. It is now news worthy to Wikipedia, where it will live forever under Criticisms (unfortunately, it appears PayPal does a lot of questionable things so its just one of a long list). Jeff _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: PayPal.com XSS Vulnerability, (continued)
- Message not available
- Re: PayPal.com XSS Vulnerability Robert Kugler (May 27)
- Message not available
- Re: PayPal.com XSS Vulnerability Jeffrey Walton (May 27)
- Re: PayPal.com XSS Vulnerability Dan Kaminsky (May 28)
- Re: PayPal.com XSS Vulnerability Jeffrey Walton (May 28)
- Re: PayPal.com XSS Vulnerability Daniël W . Crompton (May 28)
- Re: PayPal.com XSS Vulnerability Zachary Cutlip (May 28)
- Re: PayPal.com XSS Vulnerability Kirils Solovjovs (May 28)
- Re: PayPal.com XSS Vulnerability Jeffrey Walton (May 28)
- Re: PayPal.com XSS Vulnerability Terrence (May 28)
- Re: PayPal.com XSS Vulnerability Kirils Solovjovs (May 28)
- Re: PayPal.com XSS Vulnerability Źmicier Januszkiewicz (May 29)
- Re: PayPal.com XSS Vulnerability Źmicier Januszkiewicz (May 29)
- Re: PayPal.com XSS Vulnerability Julius Kivimäki (May 29)
- Re: PayPal.com XSS Vulnerability James Condron (May 29)
- Re: PayPal.com XSS Vulnerability Jeffrey Walton (May 29)
- Re: PayPal.com XSS Vulnerability James Condron (May 29)
- Re: PayPal.com XSS Vulnerability Andre Helwig (May 29)
- Re: PayPal.com XSS Vulnerability Vulnerability Lab (May 29)