REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
55
b'ooooooo_q'
49
b'jon_bottarini'
49
b'haxta4ok00'
48
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Snapchat'
disclosed a bug submitted by
b'notnaffy'
b'Administrator access to a Django Administration Panel on *.sc-corp.net via bruteforced credentials'
14 Jul 2016
b'Trello'
disclosed a bug submitted by
b'theflofly'
b'If a team is public, the web socket receives data about the Team visible boards'
14 Jul 2016
b'Trello'
disclosed a bug submitted by
b'theflofly'
b'Using WebSocket I can always access organization data even if I am removed'
14 Jul 2016
b'FantasyTote'
disclosed a bug submitted by
b'ketankumar_godhani'
b'Weak HSTS age'
14 Jul 2016
b'Gratipay'
disclosed a bug submitted by
b'ashish_goanhacker'
b'strengthen Diffie-Hellman (DH) key exchange parameters in grtp.co'
14 Jul 2016
b'Gratipay'
disclosed a bug submitted by
b'mackstaples'
b'suppress version in Server header on gratipay.com or grtp.co'
14 Jul 2016
b'OLX'
disclosed a bug submitted by
b'mefkan'
b'XSS yaman.olx.ph'
14 Jul 2016
b'Gratipay'
disclosed a bug submitted by
b'zuh4n'
b'Directory listening in grtp.co'
14 Jul 2016
b'Gratipay'
disclosed a bug submitted by
b'dotnick'
b"don't leak server version of grtp.co in error pages"
14 Jul 2016
b'Paragon Initiative Enterprises'
disclosed a bug submitted by
b'lukasreschke'
b'Content-type sniffing leads to stored XSS in CMS Airship on Internet Explorer '
14 Jul 2016
b'Slack'
disclosed a bug submitted by
b'thisishrsh'
b'File upload over private IM channel'
13 Jul 2016
b'LocalTapiola'
disclosed a bug submitted by
b'mlitchfield'
b'Blind Stored XSS Against Lahitapiola Employees - Session and Information leakage'
13 Jul 2016
b'Uber'
disclosed a bug submitted by
b'jutsuce'
b'Directory Browsing and Open Git Repository on Uber Development Box '
13 Jul 2016
b'OLX'
disclosed a bug submitted by
b'thezawad'
b'XSS @ yaman.olx.ph'
13 Jul 2016
b'OLX'
disclosed a bug submitted by
b'thezawad'
b'XSS @ *.olx.com.ar'
13 Jul 2016
b'Gratipay'
disclosed a bug submitted by
b'thezawad'
b'prevent null bytes in email field'
13 Jul 2016
b'Gratipay'
disclosed a bug submitted by
b'jsshen'
b"don't serve hidden files from Nginx"
13 Jul 2016
b'New Relic'
disclosed a bug submitted by
b'daniyal_nasir'
b'No CSRF validation on Account Monitors in Synthetics Block'
12 Jul 2016
b'New Relic'
disclosed a bug submitted by
b'sarwarjahan'
b'Normal user can set "Job title" of other users by Direct Object Reference'
12 Jul 2016
b'Uber'
disclosed a bug submitted by
b'maluko'
b'Information regarding trips from other users'
12 Jul 2016
1
...
606
607
608
609
610
...
715
BY DENIS WERNER - @NOBBD -
IMPRESSUM