REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Mail.Ru'
disclosed a bug submitted by
b'bobrov'
b'[qpt.mail.ru] CRLF Injection / Open Redirect'
02 Mar 2017
b'Mail.Ru'
disclosed a bug submitted by
b'bobrov'
b'[element.mail.ru] /.svn/entries'
02 Mar 2017
b'Mail.Ru'
disclosed a bug submitted by
b'bobrov'
b'[cooking.lady.mail.ru] Open Redirect'
02 Mar 2017
b'Mail.Ru'
disclosed a bug submitted by
b'bobrov'
b'[ml.money.mail.ru] Open Redirect'
02 Mar 2017
b'Slack'
disclosed a bug submitted by
b'testalways'
b'dom xss in https://www.slackatwork.com'
02 Mar 2017
b'Gratipay'
disclosed a bug submitted by
b'ant_pyne'
b'URL Given leading to end users ending up in malicious sites'
01 Mar 2017
b'shopify-scripts'
disclosed a bug submitted by
b'ston3'
b'SIGSEGV - mrb_check_intern_str() - NullPointer'
01 Mar 2017
b'shopify-scripts'
disclosed a bug submitted by
b'ston3'
b'SIGSEGV on mrb_vm_exec() Null Deref'
01 Mar 2017
b'shopify-scripts'
disclosed a bug submitted by
b'ston3'
b'SIGABRT, SIGSEGV mspace_free() and mrb_default_allocf()'
01 Mar 2017
b'shopify-scripts'
disclosed a bug submitted by
b'raydot'
b'DoS: type confusion in mrb_no_method_error'
01 Mar 2017
b'shopify-scripts'
disclosed a bug submitted by
b'ston3'
b'SIGSEGV in mrb_vm_exec'
01 Mar 2017
b'Yelp'
disclosed a bug submitted by
b'denispugachev'
b'CSRF on signup endpoint (auto-api.yelp.com)'
01 Mar 2017
b'Khan Academy'
disclosed a bug submitted by
b'dermeister'
b"The web app's forgot password page is vulnerable to text injection/content spoofing"
01 Mar 2017
b'shopify-scripts'
disclosed a bug submitted by
b'brakhane'
b'Crash: Overwriting NoMethodError with a builtin class crashes/corrupts memory'
01 Mar 2017
b'Starbucks'
disclosed a bug submitted by
b'ak1t4'
b'SAP Server - default credentials enabled'
28 Feb 2017
b'Starbucks'
disclosed a bug submitted by
b'kylecolson'
b'Brute Force Attack against PIN on Card History Page Could Lead to Card Information Discovery / Fraud'
28 Feb 2017
b'Slack'
disclosed a bug submitted by
b'fransrosen'
b'Stealing xoxs-tokens using weak postMessage / call-popup redirect to current team domain'
28 Feb 2017
b'shopify-scripts'
disclosed a bug submitted by
b'aerodudrizzt'
b"segafult in mruby's sprintf - mrb_str_format"
28 Feb 2017
b'Snapchat'
disclosed a bug submitted by
b'kontez'
b'RTLO char allowed in chat'
28 Feb 2017
b'shopify-scripts'
disclosed a bug submitted by
b'ssarong'
b'Heap Buffer overflow in mrb_ary_unshift'
28 Feb 2017
1
...
575
576
577
578
579
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM