Every few weeks I get an email that goes something like this:
Hi, I’m an ethical hacker and I found some security vulnerabilities in your site. Attached is proof.
I expect a reward for this information, can you let me know how much you will pay, or should I share this exploit online?
——— Now, none of the issues are very serious, nobody has been able to access data they shouldn’t have, they’re usually small things about header, XSS etc, but nevertheless valid.
I can’t really afford to pay them, and buy I also don’t want to suffer reputation loss.
At the same time, I don’t k ow that it’s realistic to have zero security recommendations as pretty much any project I’ve ever seen has some… although it’s a worthy target.
Any recommendations on how to deal with this?
1. Ignore them? 2. Pay them? 3. Thank them and ask them to move on
I usually fix the problem and to (3), but it’s concerning behaviour that seems to be increasing in frequency.
Hire an external auditor and have your code checked properly, because it's only a matter of time before someone finds the 'big one' and that they won't tell you about.
You could also explain your financial circumstances (not too much detail) and offer a small amount.
IME many of these inquiry are happy to get a few bucks - and the feather for the cap.
Also, a code audit would be in order.