REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
64
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Twitter'
disclosed a bug submitted by
b'safehacker_27'
b'Accepting error message on twitter sends you to attacker site'
13 Mar 2020
b'Mail.ru'
disclosed a bug submitted by
b'hackervision'
b'Brute-force any email account through allods.mail.ru '
13 Mar 2020
b'Ping Identity'
disclosed a bug submitted by
b'jackb898'
b'Internal Hostname disclosure from multiple Apache servers via blank host header method'
12 Mar 2020
b'Twitter'
disclosed a bug submitted by
b'meepmerp'
b'lack of input validation that can lead Denial of Service (DOS)'
12 Mar 2020
b'TTS Bug Bounty'
disclosed a bug submitted by
b'nathand'
b'Cache poisoning DoS to various TTS assets'
12 Mar 2020
b'BCM Messenger'
disclosed a bug submitted by
b'namunah'
b'Account Takeover with old password and login QR'
12 Mar 2020
b'Revive Adserver'
disclosed a bug submitted by
b'hoangn144'
b'bypass old password with array in /admin/account-user-email.php'
12 Mar 2020
b'Revive Adserver'
disclosed a bug submitted by
b'hoangn144'
b'Open redirection bypass in /www/admin/campaign-modify.php'
12 Mar 2020
b'HackerOne'
disclosed a bug submitted by
b'tolo7010'
b'Disabled account can still use GraphQL endpoint'
12 Mar 2020
b'Slack'
disclosed a bug submitted by
b'defparam'
b'Mass account takeovers using HTTP Request Smuggling on https://slackb.com/ to steal session cookies'
12 Mar 2020
b'Slack'
disclosed a bug submitted by
b'sandrogauci'
b'Slack DTLS uses a private key that is in the public domain, which may lead to SRTP stream hijack'
12 Mar 2020
b'Slack'
disclosed a bug submitted by
b'sandrogauci'
b'TURN server allows TCP and UDP proxying to internal network, localhost and meta-data services'
12 Mar 2020
b'Monero'
disclosed a bug submitted by
b'consistent-dream'
b'Monero wallet password change is confirmed when not matching'
11 Mar 2020
b'Monero'
disclosed a bug submitted by
b'ahook'
b'Potential linkage of public/private (anonymous) node addresses'
11 Mar 2020
b'HackerOne'
disclosed a bug submitted by
b'jobert'
b'HackerOne Pentesters can access any structured scope object through GraphQL node interface'
11 Mar 2020
b'Razer'
disclosed a bug submitted by
b'0x496'
b'Reflected XSS on molpay.com with cloudflare bypass'
11 Mar 2020
b'Razer'
disclosed a bug submitted by
b's3cr3tsdn'
b'Insecure Processing of XML leads to Denial of Service through Billion Laughs Attack'
11 Mar 2020
b'Razer'
disclosed a bug submitted by
b'l00ph0le'
b'Store Cross-Site Scripting - www.razer.ru'
11 Mar 2020
b'Razer'
disclosed a bug submitted by
b't3ngu'
b' Information disclosure at http://sea-s2s.molthailand.com/status.php'
11 Mar 2020
b'Razer'
disclosed a bug submitted by
b'nnez'
b'Leftover back-end system on www.zest.co.th allows an unauthorized attacker to generate Razer Gold Pin for free'
11 Mar 2020
1
...
327
328
329
330
331
...
744
BY DENIS WERNER - @NOBBD -
IMPRESSUM