REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Nextcloud'
disclosed a bug submitted by
b'roshanpty'
b'The application uses basic authentication.'
18 Jul 2016
b'Mail.Ru'
disclosed a bug submitted by
b'hunter'
b'Possibility to attach any mobile number to any email'
18 Jul 2016
b'OLX'
disclosed a bug submitted by
b'c4u53'
b'Reflected XSS at yaman.olx.ph'
18 Jul 2016
b'Nextcloud'
disclosed a bug submitted by
b'secureashishpathak'
b'nextcloud.com: Mail Bombing ( No Rate Limiting On Sending Emails On Contact us Page)'
17 Jul 2016
b'Shopify'
disclosed a bug submitted by
b'fin1te'
b'Potentially Sensitive Information on GitHub'
17 Jul 2016
b'Shopify'
disclosed a bug submitted by
b'fin1te'
b'Authentication Bypass on Icinga monitoring server'
17 Jul 2016
b'Gratipay'
disclosed a bug submitted by
b'roshanpty'
b'The contribution save option seem to be vulnerable to CSRF'
17 Jul 2016
b'Nextcloud'
disclosed a bug submitted by
b'arbaz_hussain'
b'stats.nextcloud.com: Content Injection'
17 Jul 2016
b'Ian Dunn'
disclosed a bug submitted by
b'hacklikeapro'
b'User enumeration in wp-admin'
16 Jul 2016
b'Ian Dunn'
disclosed a bug submitted by
b'anant'
b'Multiple Path Disclosure'
16 Jul 2016
b'Xero'
disclosed a bug submitted by
b'psychomantis'
b'Additonal stored XSS in Add note/Expected payment Date'
16 Jul 2016
b'HackerOne'
disclosed a bug submitted by
b'yaworsk'
b'Report title and issue information prepopulated '
15 Jul 2016
b'Uber'
disclosed a bug submitted by
b'jouko'
b'OneLogin authentication bypass on WordPress sites via XMLRPC'
15 Jul 2016
b'Keybase'
disclosed a bug submitted by
b'sarwarjahan'
b'Un-handled exception leads to Information Disclosure'
15 Jul 2016
b'Gratipay'
disclosed a bug submitted by
b'secbughunter'
b'stop serving grtp.co over HTTP'
15 Jul 2016
b'Uber'
disclosed a bug submitted by
b'mongo'
b"Change any Uber user's password through /rt/users/passwordless-signup - Account Takeover (critical)"
14 Jul 2016
b'Snapchat'
disclosed a bug submitted by
b'notnaffy'
b'Administrator access to a Django Administration Panel on *.sc-corp.net via bruteforced credentials'
14 Jul 2016
b'Trello'
disclosed a bug submitted by
b'theflofly'
b'If a team is public, the web socket receives data about the Team visible boards'
14 Jul 2016
b'Trello'
disclosed a bug submitted by
b'theflofly'
b'Using WebSocket I can always access organization data even if I am removed'
14 Jul 2016
b'FantasyTote'
disclosed a bug submitted by
b'ketankumar_godhani'
b'Weak HSTS age'
14 Jul 2016
1
...
628
629
630
631
632
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM