Email · Danger Stamp warns BEG BOUNTY
The "security researcher" who wants a bounty⚠ BEG BOUNTY
A real scam people fell for this year, next to the real thing. The numbers mark the three things to check: hover or tap one to see what it tells you.
Hi Brightleaf Bakery,
As part of our regular checks, we renewed the security certificate for brightleafbakery.co.uk. Your site stays secure, with no action needed from you.
Questions? Visit the Help Center in your Squarespace account.
Hi Team, I am an independent security researcher and I found a vulnerability on your website brightleafbakery.co.uk. Your domain has no DMARC record, so anyone can send email that looks like it comes from you and phish your customers.
I have a proof of concept ready. Kindly let me know if you have a bug bounty program and what reward you will give for this finding, then I will share the full report with steps to fix.
Regards, Rahul, Security Researcher
Always check the bounty.
A stranger ran a free scanner on your site and wants to be paid for the "finding". The issue is usually minor, and paying only puts you on a list for more.
no-reply@squarespace.com is the company that hosts your site.
rahul.sec.research07@gmail.com is a stranger on a free Gmail account.
Nothing. It tells you something was done for you.
Tell him "what bounty you pay" before he shares the report.
No pressure.
Scary talk about your customers, and a report he holds back until you name a reward.
RememberA stranger who finds a "hole" in your website and asks what you pay is fishing for money. Ask your web person, don't pay.
Would you have spotted it?
10 pairs like this one, three minutes, a score to share. Then find out who in the family is the easy mark.