Answer the question
In order to leave comments, you need to log in
Am I breaking the law by crawling a site that is participating in a bug bounty?
Am I breaking the law by scanning sites for vulnerabilities that participate in bug bounty programs?
And am I violating if I crawl sites that are no longer participating or did not participate in the bug bounty?
Answer the question
In order to leave comments, you need to log in
As a rule, web applications participating in BB programs do not accept reports from automatic security analysis tools, but you can use them to search for and then interpret the results.
As for scanning resources that have not declared their participation in BB programs anywhere, well, everything is quite simple here - I like this analogy
: master keys - they don’t want to rob anyone, they just check the locks for reliability! :)
As a rule, bug bounty participants clearly state in their rules whether automatic tools can be used to identify vulnerabilities.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question