REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
65
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Zomato'
disclosed a bug submitted by
b'bhavukjain1'
b"Unauthorised Access to Anyone's User Account"
28 Mar 2017
b'Shopify'
disclosed a bug submitted by
b'zombiehelp54'
b'CSRF in all API endpoints when authenticated using HTTP Authentication'
28 Mar 2017
b'Shopify'
disclosed a bug submitted by
b'zombiehelp54'
b'Stored XSS in [shop].myshopify.com/admin/orders/[id]'
28 Mar 2017
b'Shopify'
disclosed a bug submitted by
b'skavans'
b'Stored passive XSS at scheduled posts (kitcrm.com)'
28 Mar 2017
b'Shopify'
disclosed a bug submitted by
b'jamesclyde'
b'Full access at an internal service of Shopify'
28 Mar 2017
b'YouPorn'
disclosed a bug submitted by
b'myst404'
b'Reflected XSS in Meta Tag'
28 Mar 2017
b'Pornhub'
disclosed a bug submitted by
b'cyber-guard'
b'IDOR - disclosure of private videos - /api_android_v3/getUserVideos'
27 Mar 2017
b'QIWI'
disclosed a bug submitted by
b'bobrov'
b'[ibank.qiwi.ru] UI Redressing via Request-URI'
27 Mar 2017
b'Mail.Ru'
disclosed a bug submitted by
b'paresh_parmar'
b'Potential SSRF in sales.mail.ru'
27 Mar 2017
b'Mail.Ru'
disclosed a bug submitted by
b'bigbear_'
b'[gitmm.corp.mail.ru] Auth Bypass, Information Disclosure'
27 Mar 2017
b'Mail.Ru'
disclosed a bug submitted by
b'bigbear_'
b'[allods.mail.ru] Reflected XSS'
27 Mar 2017
b'Mail.Ru'
disclosed a bug submitted by
b'bigbear_'
b'[w1.dwar.ru] Core Dump'
27 Mar 2017
b'Mail.Ru'
disclosed a bug submitted by
b'bigbear_'
b'[otus.p.mail.ru] Full Path Disclosure'
27 Mar 2017
b'QIWI'
disclosed a bug submitted by
b'bobrov'
b'[qiwi.com] .bash_history'
27 Mar 2017
b'QIWI'
disclosed a bug submitted by
b'4lemon'
b'Stored xss in agent.qiwi.com'
27 Mar 2017
b'HackerOne'
disclosed a bug submitted by
b'ak1t4'
b'Subdomain takeover at info.hacker.one'
27 Mar 2017
b'HackerOne'
disclosed a bug submitted by
b'shailesh4594'
b'Limited Open redirection using SSO-SAML'
26 Mar 2017
b'HackerOne'
disclosed a bug submitted by
b'aaron_costello'
b'Google Analytics could be used as CSP bypass for data exfiltration on hackerone.com'
26 Mar 2017
b'Udemy'
disclosed a bug submitted by
b'caffeinewriter'
b"Able to view others' gifts on /gift/share URL, giftId is predictable, and easy to manipulate"
26 Mar 2017
b'Twitter'
disclosed a bug submitted by
b'r3ligious'
b'Attacker can get vine repost user all informations even Ip address and location .'
25 Mar 2017
1
...
575
576
577
578
579
...
746
BY DENIS WERNER - @NOBBD -
IMPRESSUM