REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
55
b'ooooooo_q'
49
b'jon_bottarini'
49
b'haxta4ok00'
48
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'concrete5'
disclosed a bug submitted by
b'voodookobra'
b'Weak random number generator used in concrete/authentication/concrete/controller.php'
26 Oct 2014
b'joola.io'
disclosed a bug submitted by
b'voodookobra'
b'Weak Random Number Generator for Auth Tokens'
25 Oct 2014
b'joola.io'
disclosed a bug submitted by
b'voodookobra'
b'Timing Attack Side-Channel on API Token Verification'
25 Oct 2014
b'WePay'
disclosed a bug submitted by
b'anshuman_bh'
b'Session Fixation'
23 Oct 2014
b'HackerOne'
disclosed a bug submitted by
b'pranav_hivarekar'
b'Redirect FILTER bypass in report/comment'
19 Oct 2014
b'Coinbase'
disclosed a bug submitted by
b'anshuman_bh'
b'Leaking CSRF token over HTTP resulting in CSRF protection bypass'
16 Oct 2014
b'Mail.Ru'
disclosed a bug submitted by
b'bigbear'
b'????????? ??????? ?????????? ????'
16 Oct 2014
b'Twitter'
disclosed a bug submitted by
b'sehacure'
b'Cross site scripting on ads.twitter.com'
16 Oct 2014
b'HackerOne'
disclosed a bug submitted by
b'prakharprasad'
b'Ability to see common response titles of other teams (limited)'
15 Oct 2014
b'GlassWire'
disclosed a bug submitted by
b'bigbear'
b'Clickjacking: X-Frame-Options header missing'
12 Oct 2014
b'Square'
disclosed a bug submitted by
b'avlidienbrunn'
b'Reflected XSS in connect.square.com'
11 Oct 2014
b'WePay'
disclosed a bug submitted by
b'shahmeer_amir'
b'Session fixation in wepay.com'
10 Oct 2014
b'Greenhouse.io'
disclosed a bug submitted by
b'simon90'
b'openssh-server Forced Command Handling Information Disclosure Vulnerability on blog.greenhouse.io'
10 Oct 2014
b'HackerOne'
disclosed a bug submitted by
b'mrrm'
b'homograph attack. IDNs displyed in unicode in bug reports and on external link warning page.'
09 Oct 2014
b'IRCCloud'
disclosed a bug submitted by
b'mohdhaji87'
b'Bruteforce protection not enabled on the login page https://www.irccloud.com/'
08 Oct 2014
wont-fix
b'Flash'
disclosed a bug submitted by
b'hhj4ck'
b'Adobe Flash Player FileReference Use-after-Free Vulnerability'
07 Oct 2014
b'Flash'
disclosed a bug submitted by
b'kinine'
b'Flash Local Sandbox Bypass'
07 Oct 2014
b'Twitter'
disclosed a bug submitted by
b'simon90'
b'Twitter Flight SSL 2.0 deprecated protocol vulnerability.'
07 Oct 2014
b'Square'
disclosed a bug submitted by
b'cliffordtrigo'
b'Open Redirect [FreshBook]'
04 Oct 2014
b'Python'
disclosed a bug submitted by
b'pakt'
b'Misc Python bugs (Memory Corruption & Use After Free)'
04 Oct 2014
1
...
682
683
684
685
686
...
715
BY DENIS WERNER - @NOBBD -
IMPRESSUM