REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
81
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
60
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'RelateIQ'
disclosed a bug submitted by
b'pum'
b'Failed Certificate Validation On Custom Server (Register)'
25 Aug 2014
b'Coinbase'
disclosed a bug submitted by
b'bbohn'
b'2FA settings allowed to be changed with no delay/freeze on funds'
25 Aug 2014
wont-fix
b'Slack'
disclosed a bug submitted by
b'asdjsonyou'
b'Open Redirect login account'
25 Aug 2014
b'Slack'
disclosed a bug submitted by
b'asdjsonyou'
b'Content spoofing at Stripe Integrations'
25 Aug 2014
b'WePay'
disclosed a bug submitted by
b'pranav_hivarekar'
b'Typical form vulnerable to csrf attack'
23 Aug 2014
b'HackerOne'
disclosed a bug submitted by
b'xtross'
b'Account Hijacking (Only rare case scenario)'
23 Aug 2014
wont-fix
b'OkCupid'
disclosed a bug submitted by
b'kenb'
b'XSS in 404 page of cdn.okccdn.com'
22 Aug 2014
b'Uzbey LLC'
disclosed a bug submitted by
b'darkh4x'
b'Missing "size check" on files to upload could make memory leaks.'
22 Aug 2014
b'Slack'
disclosed a bug submitted by
b'cliffordtrigo'
b'Deleting Teams implemenation'
21 Aug 2014
wont-fix
b'WePay'
disclosed a bug submitted by
b'mrrm'
b'oauth redirect uri validation bug leads to open redirect and account compromise'
21 Aug 2014
wont-fix
b'Mavenlink'
disclosed a bug submitted by
b'cliffordtrigo'
b'Clickjacking'
21 Aug 2014
b'Yahoo!'
disclosed a bug submitted by
b'kenb'
b'XSS on Every sports.yahoo.com page'
20 Aug 2014
b'Yahoo!'
disclosed a bug submitted by
b'surgent10cross'
b'Comment Spoofing at http://suggestions.yahoo.com/detail/?prop=directory&fid=97721'
20 Aug 2014
b'Yahoo!'
disclosed a bug submitted by
b'surgent10cross'
b'CSRF Token missing on http://baseball.fantasysports.yahoo.com/b1/127146/messages'
20 Aug 2014
b'Yahoo!'
disclosed a bug submitted by
b'surgent10cross'
b'CSRF Token is missing on DELETE message option on http://baseball.fantasysports.yahoo.com/b1/127146/messages'
20 Aug 2014
b'Yahoo!'
disclosed a bug submitted by
b'internetwache'
b'Open Proxy, http://www.smushit.com/ysmush.it/, 4/09/14, #SpringClean'
20 Aug 2014
b'Yahoo!'
disclosed a bug submitted by
b'quistertow'
b'XSS in https://hk.user.auctions.yahoo.com'
20 Aug 2014
b'Yahoo!'
disclosed a bug submitted by
b'nahamsec'
b'readble .htaccess + Source Code Disclosure (+ .SVN repository)'
20 Aug 2014
b'Yahoo!'
disclosed a bug submitted by
b'cmaruti'
b'Infrastructure and Application Admin Interfaces (OWASP?CM?007)'
20 Aug 2014
b'Yahoo!'
disclosed a bug submitted by
b'cmaruti'
b'TESTING FOR REFLECTED CROSS SITE SCRIPTING (OWASP?DV?001)'
20 Aug 2014
1
...
705
706
707
708
709
...
733
BY DENIS WERNER - @NOBBD -
IMPRESSUM