<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security Concern Want To Talk In Private. in Security and Permissions</title>
    <link>https://www.dropboxforum.com/t5/Security-and-Permissions/Security-Concern-Want-To-Talk-In-Private/m-p/738309#M13080</link>
    <description>&lt;P&gt;Hello , My name is Mujtaba and i am a researcher in bugcrowd as galacticocean . i want to talk in private about a critical vulnerability that i have found in dropbox . you can give me an email address or make this post private if this is an option .&lt;/P&gt;</description>
    <pubDate>Wed, 20 Dec 2023 13:21:32 GMT</pubDate>
    <dc:creator>GalacticOcean</dc:creator>
    <dc:date>2023-12-20T13:21:32Z</dc:date>
    <item>
      <title>Security Concern Want To Talk In Private.</title>
      <link>https://www.dropboxforum.com/t5/Security-and-Permissions/Security-Concern-Want-To-Talk-In-Private/m-p/738309#M13080</link>
      <description>&lt;P&gt;Hello , My name is Mujtaba and i am a researcher in bugcrowd as galacticocean . i want to talk in private about a critical vulnerability that i have found in dropbox . you can give me an email address or make this post private if this is an option .&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 13:21:32 GMT</pubDate>
      <guid>https://www.dropboxforum.com/t5/Security-and-Permissions/Security-Concern-Want-To-Talk-In-Private/m-p/738309#M13080</guid>
      <dc:creator>GalacticOcean</dc:creator>
      <dc:date>2023-12-20T13:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: Security Concern Want To Talk In Private.</title>
      <link>https://www.dropboxforum.com/t5/Security-and-Permissions/Security-Concern-Want-To-Talk-In-Private/m-p/738319#M13081</link>
      <description>&lt;P&gt;Hey there, &lt;a href="https://www.dropboxforum.com/t5/user/viewprofilepage/user-id/1783599"&gt;@GalacticOcean&lt;/a&gt;, I hope you're doing well!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a starting point you can have a look at &lt;A href="https://dropbox.tech/security/introducing-the-dropbox-bug-bounty-program" target="_blank"&gt;this&lt;/A&gt; article.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now as for your request, would you be able to share some generic info here with us, in order to understand better what it is that you're looking for?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know more, and we'll take it from there!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 13:34:41 GMT</pubDate>
      <guid>https://www.dropboxforum.com/t5/Security-and-Permissions/Security-Concern-Want-To-Talk-In-Private/m-p/738319#M13081</guid>
      <dc:creator>Megan</dc:creator>
      <dc:date>2023-12-20T13:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Security Concern Want To Talk In Private.</title>
      <link>https://www.dropboxforum.com/t5/Security-and-Permissions/Security-Concern-Want-To-Talk-In-Private/m-p/738329#M13085</link>
      <description>Can you provide me email address so we can talk this in private without publicly disclosing .</description>
      <pubDate>Wed, 20 Dec 2023 13:53:27 GMT</pubDate>
      <guid>https://www.dropboxforum.com/t5/Security-and-Permissions/Security-Concern-Want-To-Talk-In-Private/m-p/738329#M13085</guid>
      <dc:creator>GalacticOcean</dc:creator>
      <dc:date>2023-12-20T13:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: Security Concern Want To Talk In Private.</title>
      <link>https://www.dropboxforum.com/t5/Security-and-Permissions/Security-Concern-Want-To-Talk-In-Private/m-p/738343#M13086</link>
      <description>&lt;P&gt;I have found files in a dropbox subdomain website . which can contain sensitive info like email address , password of accounts and etc which are acquired by dropbox from the customers. These files are blank because some these files are written in server side language and some are configured in a way that a user can not see it . There is no barrier between&amp;nbsp; the files and the user . user can access these files anytime without login . if you want to know the files name . ask me .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 15:29:24 GMT</pubDate>
      <guid>https://www.dropboxforum.com/t5/Security-and-Permissions/Security-Concern-Want-To-Talk-In-Private/m-p/738343#M13086</guid>
      <dc:creator>GalacticOcean</dc:creator>
      <dc:date>2023-12-20T15:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Security Concern Want To Talk In Private.</title>
      <link>https://www.dropboxforum.com/t5/Security-and-Permissions/Security-Concern-Want-To-Talk-In-Private/m-p/738355#M13089</link>
      <description>&lt;P&gt;Hey &lt;a href="https://www.dropboxforum.com/t5/user/viewprofilepage/user-id/1783599"&gt;@GalacticOcean&lt;/a&gt;, sorry for jumping in.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To report a bug/potential vulnerability to the relevant department directly, I’d suggest doing so via &lt;A href="https://bugcrowd.com/dropbox" target="_blank"&gt;Bugcrown&lt;/A&gt;, as mentioned &lt;A href="https://help.dropbox.com/security/how-security-works#:~:text=I%27m%20a%20security%20researcher%2C%20and%20I%20found%20a%20vulnerability%20with%20Dropbox.%20How%20do%20I%20report%20it%3F" target="_blank"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 15:33:40 GMT</pubDate>
      <guid>https://www.dropboxforum.com/t5/Security-and-Permissions/Security-Concern-Want-To-Talk-In-Private/m-p/738355#M13089</guid>
      <dc:creator>Nancy</dc:creator>
      <dc:date>2023-12-20T15:33:40Z</dc:date>
    </item>
  </channel>
</rss>

