# Sticky: "Help me find a security contact at XYZ company"

**URL:** https://community.disclose.io/t/sticky-help-me-find-a-security-contact-at-xyz-company/25
**Category:** Hacker Connect
**Created:** [January 27, 2021, 5:24am UTC](https://community.disclose.io/t/sticky-help-me-find-a-security-contact-at-xyz-company/25 "2021-01-27T05:24:19Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![disclose](https://yyz2.discourse-cdn.com/flex028/user_avatar/community.disclose.io/disclose/32/9_2.png) [@disclose](https://community.disclose.io/u/disclose)
#### Post date: [January 27, 2021, 5:24am UTC](https://community.disclose.io/t/sticky-help-me-find-a-security-contact-at-xyz-company/25/1 "2021-01-27T05:24:19Z")

</div>

Have you struck out trying to connect with a contact at an organization to report a vulnerability, data leak, or other security problem?

Post a new thread in this channel starting with “CONTACT ASSISTANCE” and the folks who monitor this channel will try to assist.

Please include the following:

- The name of the organization,
- Brief description of what you need,
- Any information on what you’ve tried so far.

In particular, before you post please make sure you’ve:

- Checked for contact details via [diodb](https://github.com/disclose/diodb), any security.txt listings that might exist, and on Bugcrowd/Hackerone/etc,
- Attempted contact/conversation via the recommended channels if available.

_This is a community service so please treat it with respect. Spamming, solicitation of services, and time-wasting will not be tolerated (or treated kindly)._

---

<div class="post-metadata">

### Author: ![disclose](https://yyz2.discourse-cdn.com/flex028/user_avatar/community.disclose.io/disclose/32/9_2.png) [@disclose](https://community.disclose.io/u/disclose)
#### Post date: [January 27, 2021, 5:24am UTC](https://community.disclose.io/t/sticky-help-me-find-a-security-contact-at-xyz-company/25/2 "2021-01-27T05:24:59Z")

</div>



---

<div class="post-metadata">

### Author: ![d4rkhunt3r](https://avatars.discourse-cdn.com/v4/letter/d/9fc348/32.png) [@d4rkhunt3r](https://community.disclose.io/u/d4rkhunt3r)
#### Post date: [February 4, 2021, 2:28pm UTC](https://community.disclose.io/t/sticky-help-me-find-a-security-contact-at-xyz-company/25/3 "2021-02-04T14:28:55Z")

</div>

Hi again, I hope the community could help me.

I need to report a vulnerability to **[Booking.com](http://Booking.com)**

I tried to contact them by their website, but they don’t put it easy tbh.  
DMed them in Twitter… no answer. Tagged them as well… Google dorked hoping they had a security email contact, but didn’t found anything as well.

I hope you can help me.

Thanks

---

<div class="post-metadata">

### Author: ![sickcodes](https://yyz2.discourse-cdn.com/flex028/user_avatar/community.disclose.io/sickcodes/32/29_2.png) [@sickcodes](https://community.disclose.io/u/sickcodes)
#### Post date: [February 6, 2021, 10:16am UTC](https://community.disclose.io/t/sticky-help-me-find-a-security-contact-at-xyz-company/25/4 "2021-02-06T10:16:38Z")

</div>

Hey @d4rkhunt3r!

This is pretty lame by them 🐌 if you know the specific part of the framework or application, you might be able to submit an issue on their GitHub, better yet, submit a PR.

> **[Booking.com](https://github.com/bookingcom)**
>
> Open source projects and forks of projects we use internally (for better upstream collaboration) - Booking.com

Else, you will be able to find developers who work for Booking on their GitHub and DM them on twitter.

Since they’re a holiday/seasonal and highly covid affected enterprise/company, this should be an interesting exercise!

PS: logging the issue on GitHub is also proving that you are the person or team that identified the bug.

PPS: they’re nowhere to be found on [diodb/program-list.json at master · disclose/diodb · GitHub](https://github.com/disclose/diodb/blob/master/program-list.json)  
If you do end up getting in touch with them, it would be good to submit a PR back to the diodb program database so future bounty hunters don’t have to repeat the same process!

Let us know how you go please 🙂

 ![image](https://canada1.discourse-cdn.com/flex028/uploads/disclose1/original/1X/38b9ca9b9b41afc0938621384193ee995ad203e2.jpeg)
