it is max they pay, bounty is usually not our motivation. part of this research motivation is to get tac/cvp to our org which we have been trying for long, so hope is to do good-faith research, find vulnerability, prove our work and get access to do more of this work.
we usually send bugs through security@ email if they have disclosure policy that doesn't allow publishing the bugs at cost of not getting bounty
显示更多