REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
80
b'linkks'
75
b'jobert'
70
b'someonenobbd'
62
b'nyymi'
58
b'ooooooo_q'
52
b'haxta4ok00'
49
b'jon_bottarini'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'VK.com'
disclosed a bug submitted by
b'trainzment'
b'????????? ?????????? ? ??????? ?????? ??? ??????????'
12 May 2018
b'HackerOne'
disclosed a bug submitted by
b'haxta4ok00'
b'Team object in GraphQL disclosed total number of whitelisted hackers'
12 May 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'chalker'
b'`byte` allocates uninitialized buffers and reads data from them past the initialized length'
11 May 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'chalker'
b'`base64url` allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below'
11 May 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'chalker'
b'`macaddress` concatenates unsanitized input into exec() command'
11 May 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'chalker'
b'`command-exists` concatenates unsanitized input into exec()/execSync() commands'
11 May 2018
b'Twitter'
disclosed a bug submitted by
b'lukeberner'
b'ms5 debug page exposing internal info (internal IPs, headers)'
11 May 2018
b'Mail.Ru'
disclosed a bug submitted by
b'xawdxawdx'
b'CSRF ?? calendar.mail.ru'
11 May 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'bl4de'
b"[buttle] Remote Command Execution via unsanitized PHP filename when it's run with --php-bin flag"
11 May 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'caioluders'
b'Bypass to defective fix of Path Traversal '
11 May 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'chalker'
b'`fs-path` concatenates unsanitized input into exec()/execSync() commands'
11 May 2018
b'Mail.Ru'
disclosed a bug submitted by
b'obmi'
b'XSS on e.mail.ru via postMessage'
11 May 2018
b'Node.js third-party modules'
disclosed a bug submitted by
b'chalker'
b'`stringstream` allocates uninitialized Buffers when number is passed in input stream on Node.js 4.x and below'
11 May 2018
b'ICQ'
disclosed a bug submitted by
b'whitehattushu'
b'The auth token does not expire on logging out and even after logging out all sessions'
11 May 2018
b'Mail.Ru'
disclosed a bug submitted by
b'xawdxawdx'
b'Shell upload in http://widget.support.my.com/'
11 May 2018
b'JamieWeb'
disclosed a bug submitted by
b'retr0'
b'Insecure Transportation Security Protocol Supported (TLS 1.0) on https://www.jamieweb.net'
11 May 2018
b'Rockstar Games'
disclosed a bug submitted by
b'n00bsec'
b'Table and Column Exposure'
10 May 2018
b'Udemy'
disclosed a bug submitted by
b'cha5m'
b'Subdomain Takeover (and Stored XSS) via Trailing Dot at https://coding-exercises.udemy.com'
10 May 2018
b'New Relic'
disclosed a bug submitted by
b'apapedulimu'
b'Captcha Bypass on SignUp Form'
10 May 2018
b'Inflection'
disclosed a bug submitted by
b'tolo7010'
b'Clickjacking on https://www.goodhire.com/api'
10 May 2018
1
...
450
451
452
453
454
...
727
BY DENIS WERNER - @NOBBD -
IMPRESSUM