Und wie man sieht ist das Problem auch nicht neu:
https://mastodon.social/@DocCool/115620762844478695
#openbugbounty #scam
Update: Die #OpenBugBounty #Scam-Mails machen immer noch die Runde:
--> https://cool-web.de/blog/email-openbugbounty-sicherheitsluecke-oder-spam-scam.htm
#Spam #Scam #Scareware #ITSecurity #ITSicherheit #Awareness #Email #Antiscam #Antispam
Yesterday I got a #scam email allegedly from #OpenBugBounty (from a slightly different email address, note the typo) about a vulnerability but with no details, asking to contact by email to a Gmail address.
I immediately reported to #namesilo (the domain registrar) and openbugbounty[.]org. Today the scam domain has been deactivated! That was pretty fast!
Hi #itsecurity folks. I have a question for a friend:
My friend got contacted by #OpenBugBounty about a vulnerability in his website. They say they do responsible disclosure, but in fact, they donโt disclose anything. My friend contacted the โsecurity researcherโ who found the vulnerability and that guy just asked for money. So nothing is disclosed to my friend (who thinks there probably is nothing serious, knowing his website).
So whatโs the deal? Is OpenBugBounty a blackmailing site or legit?
Why does OpenBugBounty still only support Twitter login? Surely they've seen the writing on the wall by now??
On that topic, are there any alternatives to OBB that support more traditional, non social-network related logins?
After some time of radio silence, I saw another #OpenBugBounty phishing.
It pretends to be from openbugbounty.de and try uses a gmail contact
I got my first incident reported via #OpenBugBounty. To be honest: The communication worked better than it does at my workplace.
Now I just need to convince management that these kinds of reports are worth a few bucks. ๐