+ Reply to Thread
Results 1 to 8 of 8




  

Thread: Best way to pitch for a contact.

      
  1. #1
    jon
    jon is offline
    The Force is Strong! jon is on a distinguished road jon's Avatar
    Join Date
    October 5, 2007
    Location
    Edinburgh
    Posts
    52
    Rep Power
    5
    Feedback Score
    0

    Default Best way to pitch for a contact.

    Hi,

    We have recently come across a pretty large local companies website that has a few massive gaping holes in the system. Things like parsing database query's in the URL on lots of different occasions. It would be possible to delete the entire database just with a few variable changes on a few different urls.

    Needless to say we haven't done such a thing, but we feel this site needs fixing.

    What would be the best way to pitch for this contact? I don't want the first contact we make with the company sound like a threat. More a suggestion, but wording that we could take their entire site down in a few minutes isn't going to be an easy thing to portray to a non-techy person.

    Write a proposal and email it over? Call them and try and make it sound like a suggestion and not a thread? Take their site down and make it forward to our company site? (that isn't a serious suggestion btw :lol: )

    Any help is much appreciated.

    Thanks,
    Jon

  2. #2
    Zap
    Zap is offline
    I Love Lesbians! Zap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond repute Zap's Avatar
    Join Date
    September 29, 2006
    Location
    Canada, Eh?
    Posts
    4,385
    Rep Power
    10
    Feedback Score
    0

    Default

    How about a face to face meeting with someone that starts off with...
    "Did you know that your website data is vulnerable to..."

    People who make threats, wouldn't usually do it in person, so you have the opportunity to help them stay at ease with the news, since you're there to reassure them that you have good intentions.
    You're also letting them know that there is a problem and I would even tell them how you intend to fix it.
    Toronto Forum ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ GET FREE EXPOSURE FOR YOUR BLOG!

  3. #3
    Jedi Master chaka42 is just really nicechaka42 is just really nicechaka42 is just really nicechaka42 is just really nicechaka42 is just really nicechaka42 is just really nicechaka42 is just really nicechaka42 is just really nice chaka42's Avatar
    Join Date
    February 6, 2007
    Location
    Midwest
    Posts
    359
    Rep Power
    6
    Feedback Score
    0

    Default

    Quote Originally Posted by Zap View Post
    You're also letting them know that there is a problem and I would even tell them how you intend to fix it.
    I wouldn't tell them too much, otherwise, they would just do what you propose.

    Still, the work is in convincing the company that their site is broken and that they should pay you to fix it.

  4. #4
    Zap
    Zap is offline
    I Love Lesbians! Zap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond repute Zap's Avatar
    Join Date
    September 29, 2006
    Location
    Canada, Eh?
    Posts
    4,385
    Rep Power
    10
    Feedback Score
    0

    Default

    Quote Originally Posted by chaka42 View Post
    I wouldn't tell them too much, otherwise, they would just do what you propose.

    Still, the work is in convincing the company that their site is broken and that they should pay you to fix it.
    How do you tell them their website is broken without telling them how it's broken?

    You have to give a little to get a little.
    You never know... they may appreciate the honesty and reward it with the job.

    Conversely, if someone comes to me and tells me that something's wrong with my website; they won't tell me what's wrong and won't tell me how the're going to fix it, I would view them as a little bit shady.
    Toronto Forum ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ GET FREE EXPOSURE FOR YOUR BLOG!

  5. #5
    Jedi Master dvduval has a spectacular aura aboutdvduval has a spectacular aura aboutdvduval has a spectacular aura about dvduval's Avatar
    Join Date
    January 14, 2007
    Posts
    317
    Rep Power
    6
    Feedback Score
    0

    Default

    I think honesty is always the best approach. It doesn't mean you need to show exactly how to exploit it, but you will be doing them a good service telling them about the problem even if you don't get the work. If you handle this well, you will actually build trust, but make sure you are right about this. You won't look good if there is actually no problem at all.
    Directory Script -easy to create and profitable too Demo
    Template Forums - find templates for phpLD
    phpLD Site of the Month Winners - see some great directories
    phpLD Hosting - our top hosting pick for phpLD users

  6. #6
    Jedi Master ewomack has a spectacular aura aboutewomack has a spectacular aura aboutewomack has a spectacular aura aboutewomack has a spectacular aura about ewomack's Avatar
    Join Date
    November 25, 2007
    Posts
    75
    Rep Power
    5
    Feedback Score
    0

    Default

    You do have to tell them what's wrong and give some specific description, otherwise they'll just blow you off as spam for the paranoid. You can point out the holes and the vulnerabilities and say "we know how to fix it. Can we work with your security group on a consulting basis?" If all goes well they may call you back later. Start small. Don't take over the company on the first job.
    Ed Womack
    Get Milked

  7. #7
    Zap
    Zap is offline
    I Love Lesbians! Zap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond reputeZap has a reputation beyond repute Zap's Avatar
    Join Date
    September 29, 2006
    Location
    Canada, Eh?
    Posts
    4,385
    Rep Power
    10
    Feedback Score
    0

    Default

    Quote Originally Posted by ewomack View Post
    You do have to tell them what's wrong and give some specific description, otherwise they'll just blow you off as spam for the paranoid. You can point out the holes and the vulnerabilities and say "we know how to fix it. Can we work with your security group on a consulting basis?" If all goes well they may call you back later. Start small. Don't take over the company on the first job.
    Good advice.

    I couldn't take someone seriously if they didn't give me some details.
    Toronto Forum ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ ♫ GET FREE EXPOSURE FOR YOUR BLOG!

  8. #8
    The Force is Strong! axemedia is a splendid one to beholdaxemedia is a splendid one to beholdaxemedia is a splendid one to beholdaxemedia is a splendid one to beholdaxemedia is a splendid one to beholdaxemedia is a splendid one to beholdaxemedia is a splendid one to beholdaxemedia is a splendid one to beholdaxemedia is a splendid one to beholdaxemedia is a splendid one to beholdaxemedia is a splendid one to behold axemedia's Avatar
    Join Date
    December 6, 2006
    Location
    In My Website, I Swear!
    Posts
    567
    Rep Power
    6
    Feedback Score
    0

    Default

    By being upfront with what needs fixing and how gives you an opportunity to display that you're very knowledgeable. While you're at it you can make suggestions on what else could be improved on the site or added to the site that would create real value for the business and their site.

    Impress the hell out of them and they are sure to get you to do it instead of themselves or someone else. If they happen to be the type that would just take your suggestions and pass them on to the people that usually take care of their site then, oh well, just move on to the next one.

+ Reply to Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. contact form
    By unr in forum HTML & Website Design
    Replies: 22
    Last Post: Apr 6th, 2008, 7:41 am
  2. No Contact form on wordpress??
    By Kaos in forum Blogging
    Replies: 5
    Last Post: Dec 11th, 2007, 10:12 am
  3. contact directory script?
    By bentong in forum HTML & Website Design
    Replies: 4
    Last Post: May 9th, 2007, 5:54 pm

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
WebTalkForums
WebTalkForums
Recent Forum Threads