4
R-C-D
5y

If a pentester find a very critical bug and the boss is not aware of him knowing this type of exploitation (no one is expecting him to find such flaws)

Should he report it ? Or reporting will make him suspicious ?

Comments
  • 12
    Isn't that literally his job? Why would that make him suspicious? If I'm paying for someone to find flaws in one of my program, I would like to know everything.
  • 11
    If you find a flaw, who's to say someone outside the company hasn't found that flaw.

    As an employed pentester, you having this knowledge and not reporting it makes me suspicious.
  • 3
    @M1sf3t I'm supposed to find and fix vulnerabilities :)
  • 1
    @M1sf3t I guess he is not like that ... (how do I know if he is like that? )
Add Comment