33 ms·
Pretty low bounty. The base reward for qualifying bugs is $500. If the rewards panel finds a particular bug to be severe or unusually clever, rewards of up to
by johnbatch 15y ago
Pretty low bounty.
The base reward for qualifying bugs is $500. If the rewards panel finds a particular bug to be severe or unusually clever, rewards of up to $3,133.7 may be issued.
http://googleonlinesecurity.blogspot.com/2010/11/rewarding-web-application-security.html http://googleonlinesecurity.blogspot.com/2010/11/rewarding-w...
- tptacek 15y agoFor random XSS-style things on web pages, that's a high bounty. The crazy lucrative bugs you may have heard of tend to be drive-by remote code execution in popular clientsides (like IE or Flash), and the stories about valuations tend to be apocryphal.
- baddox 15y agoEven those bounties are only for security-related bugs, one of which this doesn't appear to be.
- 0x12 15y agoSo, that gives you your BATNA for negotiations with the dark side... Either google is very confident that they don't have serious bugs or they are setting themselves up for a problem. Imagine the value of finding a serious bug in adsense or adwords.