Researcher: DJI RCE-holes offered me $500 after I found Heartbleed etc on its servers

Chinese drone-maker DJI’s bug bounty programme has been struck with fresh controversy after a security researcher claimed he was offered just $500 for reporting, among others, the years-old Heartbleed vulnerability. Infosec chap Sean Melia – no stranger to bug bounty programmes – said he discovered that DJI’s servers not only had not been patched against Heartbleed, the OpenSSL bug revealed in 2014, but were also vulnerable to SQL code injection attacks and remote code execution with root privileges.

Read full news article on The Register

 


Date:

Categorie(s):