REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'OLX'
disclosed a bug submitted by
b'f_m'
b'web cache deception in https://tradus.com lead to name/user_id enumeration and other info'
22 Sep 2019
b'OLX'
disclosed a bug submitted by
b'littlestar'
b'Reflected XSS on https://www.olx.co.id/iklan/*.html via "ad_type" parameter'
21 Sep 2019
b'Mail.ru'
disclosed a bug submitted by
b'the_predator'
b'Disable 2FA via CSRF (Leads to 2FA Bypass)'
21 Sep 2019
b'ok.ru'
disclosed a bug submitted by
b'iframe'
b'[insideok.ru] Remote Command Execution via file upload.'
20 Sep 2019
b'ICQ'
disclosed a bug submitted by
b'protex0r'
b'Code Injection in macOS Desktop Client'
20 Sep 2019
b'PuTTY (European Commission - D'
disclosed a bug submitted by
b'niky1235'
b'Heap overflow happen when receiving short length key from ssh server using ssh protocol 1'
20 Sep 2019
b'The Internet'
disclosed a bug submitted by
b'pwnsdx'
b'Mailsploit: a sender spoofing bug in over 30 email clients'
19 Sep 2019
b'GitLab'
disclosed a bug submitted by
b'vijay_kumar1110'
b'Add and Access to Labels of any Private Projects/Groups of Gitlab(IDOR)'
19 Sep 2019
b'Ubiquiti Inc.'
disclosed a bug submitted by
b'linkks'
b'JetBrains .idea project directory'
19 Sep 2019
b'Zomato'
disclosed a bug submitted by
b'chajer'
b'Information Disclosure through Sentry Instance ???????'
19 Sep 2019
b'OLX'
disclosed a bug submitted by
b'nullcod3r'
b'Reflected XSS in www.olx.co.id'
19 Sep 2019
b'Twitter'
disclosed a bug submitted by
b'anshuman_pattnaik'
b'AppLovin API Key hardcoded in a Github repo'
18 Sep 2019
b'Shopify'
disclosed a bug submitted by
b'eissen5c'
b'Clickjacking in [exchangemarketplace.com]'
18 Sep 2019
b'VK.com'
disclosed a bug submitted by
b'linkks'
b'Information Disclosure (phpinfo())'
18 Sep 2019
b'VK.com'
disclosed a bug submitted by
b'linkks'
b'????? swag'
18 Sep 2019
b'Mail.ru'
disclosed a bug submitted by
b'obayda'
b'Settings page in https://support.my.com is vulnerable to clickjacking'
18 Sep 2019
b'RSK'
disclosed a bug submitted by
b'ahook'
b'Attacker can add arbitrary data to the blockchain without paying gas'
18 Sep 2019
b'RSK'
disclosed a bug submitted by
b'z3t'
b'DoS through PeerExplorer'
18 Sep 2019
b'Valve'
disclosed a bug submitted by
b'nyancat0131'
b'Unchecked weapon id in WeaponList message parser on client leads to RCE'
17 Sep 2019
b'Valve'
disclosed a bug submitted by
b'nyancat0131'
b'Malformed map detailed texture files in GoldSrc games lead to Remote Code Execution'
17 Sep 2019
1
...
366
367
368
369
370
...
730
BY DENIS WERNER - @NOBBD -
IMPRESSUM