Bug Bounties, Broken Promises
漏洞赏金计划承诺双赢,但部分企业利用“不会修复”标签、狭窄范围或静默补丁规避支付。研究人员投入大量时间却无回报,真实攻击链被归为“范围外”。 2025-7-20 05:2:58 Author: infosecwriteups.com(查看原文) 阅读量:19 收藏

Andrei Ivan

Bug Bounties, Broken Promises — Real stories of “won’t-fix” tags, scope tricks, and silent patches

Bug bounty platforms sell a simple dream: hackers earn money, companies get safer software, and everyone wins. But dig into public disclosure threads, Reddit rants, and private Discords and you’ll find a darker subplot. Some organizations game their own programs. Dodging payouts with “won’t fix” labels, razor-thin scopes, or last-minute severity downgrades while quietly pushing patches.

Below you’ll find three common tactics, three representative case studies, and a condensed playbook that helps new hunters stay paid (and sane) in a sometimes-rigged arena.

1. “Valid but Won’t Fix”

How It Works: Company admits the bug is real but claims the risk is acceptable, so no bounty.

Why It Hurts Hunters: Hours of research go unrewarded; no public credit.

2. Scope as a Shield

How It Works: Programs exclude high-risk assets or domains; any bug there is auto-rejected.

Why It Hurts Hunters: Real-world attack chains become “out of scope” fiction.


文章来源: https://infosecwriteups.com/bug-bounties-broken-promises-a19557db0aaa?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh