Company
Date Published
Author
Özgür Alp
Word count
1315
Language
-
Hacker News points
None

Summary

Özgür Alp, an experienced ethical hacker with over seven years in offensive security, successfully uncovered a significant vulnerability by transforming an open redirect issue into a publicly disclosed vulnerability, CVE-2020-1323, with the support of the Detectify Crowdsource team. Initially discovered during a routine bug bounty program, the vulnerability was linked to Microsoft SharePoint but was initially deemed out-of-scope by Microsoft due to the low impact nature of URL redirects. Persistence paid off when Alp reported the finding to Detectify, a platform that accepts open redirect reports irrespective of the vendor. This led to the development of a live module and a coordinated effort for responsible disclosure with Microsoft, resulting in the bug being patched and recognized with a CVE assignment. Despite Microsoft's initial assessment, collaboration ultimately led to a $1200 bounty, showcasing the value of persistence and teamwork in vulnerability disclosure.