官术网_书友最值得收藏!

Writing impact of a report

This is also an important factor in a bug bounty report. At this point, the security team has a clear idea about the vulnerability and they are aware that the threat is significant. By adding in your report, the impact of this vulnerability would help them escalate this to higher levels if needs be.

Bear in mind that the report goes through different people and the program owners have to convince the developers that the vulnerability is something worth fixing. Adding a real-world impact statement greatly helps in that and it also helps the reader of the report understand what the vulnerability is all about. The best way to help the development team understand the vulnerability and its severity and also get a good bounty is to add the impact section in your report.

Consider yourself as one of the program owners and assume what is best for them. If it's a fintech company, if the vulnerability you found exposes financial data, you should highlight that. If it's a Health Tech company and the vulnerability you found exposes patients' data, you should highlight that. That being said, you should never push your report or make it sound like it is emphasizing too much. That will result in poor delivery. Always know that there is a fine line between everything.

主站蜘蛛池模板: 德州市| 浙江省| 水富县| 惠安县| 馆陶县| 罗山县| 汉寿县| 南平市| 赤壁市| 丰顺县| 龙泉市| 突泉县| 获嘉县| 溧阳市| 拉孜县| 乌鲁木齐县| 铜梁县| 冷水江市| 芦溪县| 麻栗坡县| 海淀区| 昌都县| 徐汇区| 县级市| 呼伦贝尔市| 龙陵县| 蒙阴县| 平谷区| 抚州市| 晴隆县| 濮阳市| 革吉县| 巴楚县| 巨鹿县| 浦县| 青海省| 琼中| 西安市| 石台县| 邹城市| 瓮安县|