1. 脆弱性の報告

について、ここに記述してください。

レンタルサーバー運営会社に不正利用を通報したときの窓口と、各社の対応をまとめた。 https://qiita.com/retrorocket/items/41e7bf90aab6017c4275

Top 5 Bug Bounty Platforms to Watch in 2021 https://thehackernews.com/2021/02/top-5-bug-bounty-programs-to-watch-in.html

1.1. openbugbounty

pay-easy.jp Cross Site Scripting Vulnerability. Report ID: OBB-1921454 https://www.openbugbounty.org/reports/1921454/

Coordinated Disclosure Timeline

Vulnerability Reported: 24 February, 2021 12:59 GMT
Vulnerability Verified: 24 February, 2021 13:12 GMT

Website Operator Notified:      24 February, 2021 13:12 GMT
a. Using the ISO 29147 guidelines       
b. Using publicly available security contacts   
c. Using Open Bug Bounty notification framework 
d. Using security contacts provided by the researcher   
Public Report Published [without any technical details]: 24 February, 2021 13:12 GMT
Scheduled Public Disclosure:  Information       25 May, 2021 12:59 GMT

この手順は参考になるだろうか。

MoinQ: 脆弱性の報告 (last edited 2021-03-02 00:49:20 by ToshinoriMaeno)