Public Disclosure Policies (by Commercial websites)

  • Paypal Site Security Researchers
  • Facebook Report a Possible Security Vulnerability
  • Vulnerability Reporting Policy
  • Wesabe Contacting Security - We want to hear from you (, GPG key
  • Microsoft (link?)

Question: What types of vulnerability testing is implicitly allowed? (XSS, SQLi,,XSRF)