Ich glaube es gibt eine Gruppe die scanned systematisch den IPv4 Adressraum und wenn da irgendwo eine neue Woltlab Suite Instanz auftaucht feuern die eine Openbugbounty Scam Mail raus.
Und wie man sieht ist das Problem auch nicht neu:
https://mastodon.social/@DocCool/115620762844478695

#openbugbounty #scam
Does anyone actually look at the #OpenBugBounty platform's contact page? My account over there has added a random Twitter account and there doesn't seem to be a way to remove it. I have no idea WTF is going on.

Yesterday I got a #scam email allegedly from #OpenBugBounty (from a slightly different email address, note the typo) about a vulnerability but with no details, asking to contact by email to a Gmail address.

I immediately reported to #namesilo (the domain registrar) and openbugbounty[.]org. Today the scam domain has been deactivated! That was pretty fast!

Hi #itsecurity folks. I have a question for a friend:
My friend got contacted by #OpenBugBounty about a vulnerability in his website. They say they do responsible disclosure, but in fact, they donโ€™t disclose anything. My friend contacted the โ€œsecurity researcherโ€ who found the vulnerability and that guy just asked for money. So nothing is disclosed to my friend (who thinks there probably is nothing serious, knowing his website).

So whatโ€™s the deal? Is OpenBugBounty a blackmailing site or legit?

Why does OpenBugBounty still only support Twitter login? Surely they've seen the writing on the wall by now??

On that topic, are there any alternatives to OBB that support more traditional, non social-network related logins?

#openbugbounty #twitter #security

After some time of radio silence, I saw another #OpenBugBounty phishing.

It pretends to be from openbugbounty.de and try uses a gmail contact

Open Bug Bounty: Mehr als eine Million Schwachstellen behoben

Open Bug Bounty bringt seit 2014 Tausende von Sicherheitsforschern mit Webseitenbetreibern zusammen. Dennoch ist Vorsicht geboten.

Tarnkappe.info

I got my first incident reported via #OpenBugBounty. To be honest: The communication worked better than it does at my workplace.

Now I just need to convince management that these kinds of reports are worth a few bucks. ๐Ÿ™„