Recently, we've received several emails from individuals claiming to have found vulnerabilities on our website and requesting a reward, typically in the form of a cash bounty. Some of these vulnerabilities are ones we were already aware of, while others are new to us.
Have you encountered similar situations?
Here are a few questions we're grappling with:
1. What is a reasonable reward for such findings? We're curious about the range of bounties others are offering. How do you determine the amount?
2. How do you manage communication with these individuals? What's the best way to handle their requests professionally and maintain a positive relationship?
Any advice, best practices, or insights would be greatly appreciated!