REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'haxta4ok00'
49
b'jon_bottarini'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'itBit Exchange'
disclosed a bug submitted by
b'zoczus'
b'Notification Emails: IP + Content-Spoofing '
27 Feb 2015
b'itBit Exchange'
disclosed a bug submitted by
b'4lemon'
b'Unsecure data in "device" response - OTP'
27 Feb 2015
b'HackerOne'
disclosed a bug submitted by
b'siddiki'
b'Team member invitations to sandboxed teams are not invalidated consistently (v2)'
27 Feb 2015
b'PHP'
disclosed a bug submitted by
b'ryat'
b'Use after free vulnerability in unserialize() with DateTimeZone'
27 Feb 2015
b'99designs'
disclosed a bug submitted by
b'pranav_hivarekar'
b"CSRF to connect attacker's twitter account to logged in victims account"
26 Feb 2015
b'Greenhouse.io'
disclosed a bug submitted by
b'fransrosen'
b'Subdomain Takeover using blog.greenhouse.io pointing to Hubspot'
26 Feb 2015
b'Vimeo'
disclosed a bug submitted by
b'tfairane'
b'Vimeo.com Insecure Direct Object References Reset Password'
26 Feb 2015
b'Vimeo'
disclosed a bug submitted by
b'avlidienbrunn'
b'Adding profile picture to anyone on Vimeo'
26 Feb 2015
b'HackerOne'
disclosed a bug submitted by
b'danlec'
b'CSP Bypass: Click handler for links with data-method="post" can cause authenticity_token to be sent off domain'
26 Feb 2015
b'Todoist'
disclosed a bug submitted by
b'cliffordtrigo'
b'Taking over a Business Account Admin'
26 Feb 2015
b'Todoist'
disclosed a bug submitted by
b'cliffordtrigo'
b'Remotely removing credit cards from business accounts!'
26 Feb 2015
b'Twitter'
disclosed a bug submitted by
b'config'
b"User's DM won't deleted after logout from Twitter for iOS (com.atebits.xxx.application-state)"
25 Feb 2015
b'Twitter'
disclosed a bug submitted by
b'homakov'
b'Redirect URL in /intent/ functionality is not properly escaped'
24 Feb 2015
b'Square'
disclosed a bug submitted by
b'mikkz'
b'XSS on bookfresh'
23 Feb 2015
b'Square'
disclosed a bug submitted by
b'avicoder'
b'HTTP Header revealing server information.'
23 Feb 2015
wont-fix
b'Vimeo'
disclosed a bug submitted by
b'batram'
b'XSS on any site that includes the moogaloop flash player | deprecated embed code '
22 Feb 2015
b'Twitter'
disclosed a bug submitted by
b'simon90'
b'URGENT - SUBDOMAIN TAKEOVER ON TWITTER ACQ.'
21 Feb 2015
b'OkCupid'
disclosed a bug submitted by
b'bitquark'
b'Rosetta flash vulnerability in clientstats AJAX script'
20 Feb 2015
b'Twitter'
disclosed a bug submitted by
b'avicoder'
b'Path disclosure in platform0.twitter.com'
20 Feb 2015
wont-fix
b'HackerOne'
disclosed a bug submitted by
b'anshuman_bh'
b'Insecure Direct Object Reference vulnerability'
20 Feb 2015
1
...
686
687
688
689
690
...
726
BY DENIS WERNER - @NOBBD -
IMPRESSUM