REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
55
b'ooooooo_q'
49
b'jon_bottarini'
49
b'haxta4ok00'
48
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'DC Compendium'
disclosed a bug submitted by
b'huzaifa_82'
b'Forward Secrecy is disable'
01 Aug 2014
wont-fix
b'DC Compendium'
disclosed a bug submitted by
b'shahmeer_amir'
b'Backend source code disclosure on 404 pages'
01 Aug 2014
b'Secret'
disclosed a bug submitted by
b'denull'
b'ClientId gives away platform (iOS/Android) from which a secret was posted.'
01 Aug 2014
b'Yahoo!'
disclosed a bug submitted by
b'redshark1802'
b'Cross-origin issue on rmaiauth.ads.vip.bf1.yahoo.com'
31 Jul 2014
b'Yahoo!'
disclosed a bug submitted by
b'redshark1802'
b'Header injection on rmaitrack.ads.vip.bf1.yahoo.com'
31 Jul 2014
b'Mavenlink'
disclosed a bug submitted by
b'mikkz'
b'Login CSRF'
31 Jul 2014
b'Uzbey LLC'
disclosed a bug submitted by
b'faisalahmed'
b'All Active user sessions should be destroyed when user change his password!'
30 Jul 2014
b'DC Compendium'
disclosed a bug submitted by
b'smiegles'
b'Error page Cross-site scripting'
30 Jul 2014
b'jsDelivr'
disclosed a bug submitted by
b'shubham'
b'XSS'
29 Jul 2014
b'jsDelivr'
disclosed a bug submitted by
b'shahmeer_amir'
b'HSTS Policy not enabled on cdn.jsdelivr.net'
29 Jul 2014
wont-fix
b'4chan'
disclosed a bug submitted by
b'reactors08'
b'XSS in settings'
28 Jul 2014
b'Slack'
disclosed a bug submitted by
b'sehacure'
b'CSRF vulnerability on https://sehacure.slack.com/account/settings'
26 Jul 2014
b'Coinbase'
disclosed a bug submitted by
b'anshuman_bh'
b'CSRF on "Set as primary" option on the accounts page'
26 Jul 2014
b'RelateIQ'
disclosed a bug submitted by
b'pum'
b'SSRF (Portscan) via Register Function (Custom Server)'
26 Jul 2014
b'HackerOne'
disclosed a bug submitted by
b'sehacure'
b'Category- Broken Authentication and Session Management (leads to account compromise if some conditions are met)'
26 Jul 2014
b'RelateIQ'
disclosed a bug submitted by
b'cliffordtrigo'
b'TRACE disclosure attack may be possible'
25 Jul 2014
b'WePay'
disclosed a bug submitted by
b'cliffordtrigo'
b'CSRF & Nonce Token Weak Implementation'
25 Jul 2014
b'The Internet'
disclosed a bug submitted by
b'donb'
b'LZ4 Core'
25 Jul 2014
b'Mavenlink'
disclosed a bug submitted by
b'panchocosil'
b'Flash XSS on swfupload.swf showing at app.mavenlink.com'
24 Jul 2014
b'Uzbey LLC'
disclosed a bug submitted by
b'karthic'
b'Language version disclosure in response header '
23 Jul 2014
1
...
691
692
693
694
695
...
715
BY DENIS WERNER - @NOBBD -
IMPRESSUM