upvote
Yeah I reported an in-house dev environment vulnerability to Anthropic 2 months before the Claude code source leak. It was downgraded to “informative” and they asked me to prove that I could exfiltrate data. I replied that exfiltrating data is against their program’s safe harbor policy and they just never responded.
reply
Most bounty programs won't pay for DoS at all.
reply
it isn't simple request flooding, it is application level resource exhaustion
reply
Yeah, I figured that's what you meant, and most bounty programs won't pay out for stuff like that. Every application has those bugs; on a software pentest, we'd sev:lo them.
reply