REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
84
b'linkks'
75
b'jobert'
70
b'nyymi'
67
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Pornhub'
disclosed a bug submitted by
b'justas_b'
b'Single User DOS by Poisoning Cookie via Get Parameter'
03 Aug 2019
b'HackerOne'
disclosed a bug submitted by
b'asad0x01_'
b'Total bounties paid amount is disclosed because of redesign of the Program Profiles'
02 Aug 2019
b'Khan Academy'
disclosed a bug submitted by
b'red_assassin'
b'RTL override char allowed at https://www.khanacademy.org/computer-programming/link_redirector?url=*'
02 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'theappsec'
b'[lootdog.io] User phone number disclosure'
02 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'godexmachine'
b'[https://pandao.ru] - PUT method available'
02 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'secator'
b'[XSS] iframe ? payments/phones'
02 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'secator'
b'[XSS] data-url ? ???????'
02 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'ilyailya'
b'??? ????????? lootdog ? ??????????? ?? ?????????.'
02 Aug 2019
b'Mail.ru'
disclosed a bug submitted by
b'bobrov'
b'[o2.mail.ru] nginx alias traversal'
02 Aug 2019
b'Nextcloud'
disclosed a bug submitted by
b'j4tayu'
b'SignUp using Fake Email'
02 Aug 2019
b'Grammarly'
disclosed a bug submitted by
b'metnew'
b"Handling of `tracking` command allows making arbitrary blind requests with user's cookies from Grammarly Extension's origin"
01 Aug 2019
b'Kartpay'
disclosed a bug submitted by
b'c00lbugs'
b'Error Page Content Spoofing or Text Injection [https://vpn.kartpay.com/]'
01 Aug 2019
b'OLX'
disclosed a bug submitted by
b'codeslayer137'
b'Cross-site Scripting (XSS) - Reflected'
31 Jul 2019
b'TTS Bug Bounty'
disclosed a bug submitted by
b'tikoo_sahil'
b'Improper Session management can cause account takeover[https://micropurchase.18f.gov]'
30 Jul 2019
b'U.S. Dept Of Defense'
disclosed a bug submitted by
b'hackerfactor'
b'Gateway information leakage'
30 Jul 2019
b'PayPal'
disclosed a bug submitted by
b'born2hack'
b'IDOR to add secondary users in www.paypal.com/businessmanage/users/api/v1/users'
30 Jul 2019
b'TTS Bug Bounty'
disclosed a bug submitted by
b'tolo7010'
b'Nginx misconfiguration leading to direct PHP source code download'
29 Jul 2019
b'TTS Bug Bounty'
disclosed a bug submitted by
b'noobzombie'
b'Unclaimed Github Repository Takeover on https://www.data.gov/labs'
29 Jul 2019
b'TTS Bug Bounty'
disclosed a bug submitted by
b'omnicient'
b'Root user disclosure in data.gov domain though x-amz-meta-s3cmd-attrs header'
29 Jul 2019
b'Nextcloud'
disclosed a bug submitted by
b'doragon'
b'SQLi allow query restriction bypass on exposed FileContentProvider'
29 Jul 2019
1
...
398
399
400
401
402
...
752
BY DENIS WERNER - @NOBBD -
IMPRESSUM