REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'haxta4ok00'
49
b'jon_bottarini'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Pornhub'
disclosed a bug submitted by
b'cyber-guard'
b'IDOR - disclosure of private videos - /api_android_v3/getUserVideos'
27 Mar 2017
b'QIWI'
disclosed a bug submitted by
b'bobrov'
b'[ibank.qiwi.ru] UI Redressing via Request-URI'
27 Mar 2017
b'Mail.Ru'
disclosed a bug submitted by
b'paresh_parmar'
b'Potential SSRF in sales.mail.ru'
27 Mar 2017
b'Mail.Ru'
disclosed a bug submitted by
b'bigbear_'
b'[gitmm.corp.mail.ru] Auth Bypass, Information Disclosure'
27 Mar 2017
b'Mail.Ru'
disclosed a bug submitted by
b'bigbear_'
b'[allods.mail.ru] Reflected XSS'
27 Mar 2017
b'Mail.Ru'
disclosed a bug submitted by
b'bigbear_'
b'[w1.dwar.ru] Core Dump'
27 Mar 2017
b'Mail.Ru'
disclosed a bug submitted by
b'bigbear_'
b'[otus.p.mail.ru] Full Path Disclosure'
27 Mar 2017
b'QIWI'
disclosed a bug submitted by
b'bobrov'
b'[qiwi.com] .bash_history'
27 Mar 2017
b'QIWI'
disclosed a bug submitted by
b'4lemon'
b'Stored xss in agent.qiwi.com'
27 Mar 2017
b'HackerOne'
disclosed a bug submitted by
b'ak1t4'
b'Subdomain takeover at info.hacker.one'
27 Mar 2017
b'HackerOne'
disclosed a bug submitted by
b'shailesh4594'
b'Limited Open redirection using SSO-SAML'
26 Mar 2017
b'HackerOne'
disclosed a bug submitted by
b'aaron_costello'
b'Google Analytics could be used as CSP bypass for data exfiltration on hackerone.com'
26 Mar 2017
b'Udemy'
disclosed a bug submitted by
b'caffeinewriter'
b"Able to view others' gifts on /gift/share URL, giftId is predictable, and easy to manipulate"
26 Mar 2017
b'Twitter'
disclosed a bug submitted by
b'r3ligious'
b'Attacker can get vine repost user all informations even Ip address and location .'
25 Mar 2017
b'CloudFlare'
disclosed a bug submitted by
b'bobrov'
b'[http2.cloudflare.com] Open Redirect'
24 Mar 2017
b'Harvest'
disclosed a bug submitted by
b'zuh4n'
b"Cookie Injection at 'harvestapp.com'"
24 Mar 2017
b'OWOX, Inc.'
disclosed a bug submitted by
b'haxormad'
b'Subdomain takeover in many subdomains'
24 Mar 2017
b'Airbnb'
disclosed a bug submitted by
b'dr-cdqh'
b'Nginx Version Disclosure'
23 Mar 2017
b'Nextcloud'
disclosed a bug submitted by
b'bagipro'
b'Android - Possible to intercept broadcasts about uploaded files'
23 Mar 2017
b'Nextcloud'
disclosed a bug submitted by
b'ryudox'
b'Server version/OS type disclosure via HTTP Response Header'
23 Mar 2017
1
...
556
557
558
559
560
...
726
BY DENIS WERNER - @NOBBD -
IMPRESSUM