REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Legal Robot'
disclosed a bug submitted by
b'todayisnew'
b'Domain takeover (legalrobot.co.za)'
17 Jul 2017
b'Rockstar Games'
disclosed a bug submitted by
b'netfuzzer'
b'XSS in http://www.rockstargames.com/theballadofgaytony/js/jquery.base.js'
17 Jul 2017
b'Mail.Ru'
disclosed a bug submitted by
b'haxta4ok00'
b'????? basic ??????????? [qpt.mail.ru]'
17 Jul 2017
b'ICQ'
disclosed a bug submitted by
b'linkks'
b'Apache Server-Status Detected'
17 Jul 2017
b'Mixmax'
disclosed a bug submitted by
b'konkakarthik'
b'mailbomb through invite feature on chrome addon'
16 Jul 2017
b'HackerOne'
disclosed a bug submitted by
b'h33t'
b'Invitation tokens leak to Google Analytics'
16 Jul 2017
b'Mixmax'
disclosed a bug submitted by
b'michan001'
b'no string size restriction on team name'
16 Jul 2017
b'Legal Robot'
disclosed a bug submitted by
b'goodhackonly'
b'Missing link to 2FA recovery code'
15 Jul 2017
b'Slack'
disclosed a bug submitted by
b'fbogner'
b"Code Injection in Slack's Windows Desktop Client leads to Privilege Escalation"
14 Jul 2017
b'Nextcloud'
disclosed a bug submitted by
b'xyberwolf'
b'Directory Listing In Subdomain Of nextcloud.com'
14 Jul 2017
b'WordPress'
disclosed a bug submitted by
b'eidelweiss'
b'Stored self-XSS in mercantile.wordpress.org checkout'
14 Jul 2017
b'concrete5'
disclosed a bug submitted by
b'bl4de'
b'Stored XSS in Headline TextControl element in Express forms [ concrete5 8.1.0 ]'
14 Jul 2017
b'ToyTalk'
disclosed a bug submitted by
b'saidon_1015'
b'Host Header Injection and Cache Poisoning'
13 Jul 2017
b'Uber'
disclosed a bug submitted by
b'arneswinnen'
b'Authentication bypass on auth.uber.com via subdomain takeover of saostatic.uber.com'
13 Jul 2017
b'Mapbox'
disclosed a bug submitted by
b'sahilsaif'
b'Public access to objects in AWS S3 bucket'
12 Jul 2017
b'Trello'
disclosed a bug submitted by
b'b14ck_eye'
b'Unpatched (https://hackerone.com/reports/221928)- Unviladate File Upload to XSS on trello-attachment Bucket'
12 Jul 2017
b'Algolia'
disclosed a bug submitted by
b'an0n-j'
b'SAUCE Access_key and User_name leaked in Travis CI build logs'
12 Jul 2017
b'The Internet'
disclosed a bug submitted by
b'magnusstubman'
b'ntpd: read_mru_list() does inadequate incoming packet checks'
12 Jul 2017
b'The Internet'
disclosed a bug submitted by
b'claudijd'
b'Mercurial can be tricked into granting authorized users access to the Python debugger'
12 Jul 2017
b'Trello'
disclosed a bug submitted by
b'ajdumanhug'
b"Cross-Site Scripting on Trello's iPhone App"
12 Jul 2017
1
...
530
531
532
533
534
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM