Dropbox Shares Best Practices for Bug Bounty Submissions
Dropbox is inviting security researchers to participate in its bug bounty program, run through HackerOne and Bugcrowd. The company wants to make the submission process straightforward for everyone, from seasoned vulnerability hunters to newcomers.
To assist researchers, Dropbox's security engineers have compiled a list of five key tips for crafting effective bug reports:
- Strengthen your report by detailing the actual and potential impact of the vulnerability and how it could be exploited.
- Describe the methodology used to uncover the bug and provide clear steps to reproduce it.
- Only submit results after confirming that the vulnerability has been properly verified.
- Write the report in your native language if you are not comfortable composing it in English.
- Ensure you gain reputation through the process.
For those looking for a model to follow, Dropbox points to this example of a well-executed report: https://hackerone.com/reports/56828. The sample report features a concise description, highlights the actual and potential impact, and gives step-by-step reproduction instructions. Including these elements makes a report more useful and increases the odds that Dropbox will act on it.



