REPORTS
PROGRAMS
PUBLISHERS
Top10 publishers:
b'bobrov'
117
b'sp1d3rs'
86
b'geeknik'
83
b'linkks'
75
b'jobert'
70
b'nyymi'
62
b'someonenobbd'
62
b'ooooooo_q'
54
b'guido'
50
b'haxta4ok00'
49
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Instacart'
disclosed a bug submitted by
b'003random'
b'Bruteforcing password reset tokens, could lead to account takeover'
06 Nov 2017
b'Twitter'
disclosed a bug submitted by
b'dups'
b'CSRF in twitterflightschool.com ( CAN POST ON TIMELINE WITHOUT USER PERMISSION)'
06 Nov 2017
b'Infogram'
disclosed a bug submitted by
b'mrreboot'
b'Tabnabbing via window.opener'
06 Nov 2017
b'Infogram'
disclosed a bug submitted by
b'mrreboot'
b'Weak Password Policy on Signup'
06 Nov 2017
b'Infogram'
disclosed a bug submitted by
b'mrreboot'
b'SPF Misconfiguration'
06 Nov 2017
b'Discourse'
disclosed a bug submitted by
b'mishre'
b'Any user with invite capabilities can take-over any account on Discourse'
06 Nov 2017
b'Starbucks'
disclosed a bug submitted by
b'albinowax'
b'DOM-based XSS in store.starbucks.co.uk on IE 11'
03 Nov 2017
b'Infogram'
disclosed a bug submitted by
b'nihadrekanym'
b'XSS on Report Classic'
03 Nov 2017
b'Infogram'
disclosed a bug submitted by
b'asad90'
b'No Email Verification'
03 Nov 2017
b'Infogram'
disclosed a bug submitted by
b'tungpun'
b'Internal Ports Scanning via Blind SSRF'
03 Nov 2017
b'IRCCloud'
disclosed a bug submitted by
b'bagipro'
b'[IRCCloud Android] Opening arbitrary URLs/XSS in SAMLAuthActivity'
03 Nov 2017
b'IRCCloud'
disclosed a bug submitted by
b'bagipro'
b'[IRCCloud Android] XSS in ImageViewerActivity'
03 Nov 2017
b'Shopify'
disclosed a bug submitted by
b'sijad'
b'stored xss in invited team member via email parameter'
03 Nov 2017
b'Gratipay'
disclosed a bug submitted by
b'edio'
b'CSV injection in gratipay.com via payment history export feature.'
03 Nov 2017
b'The Internet'
disclosed a bug submitted by
b'vanhoefm'
b'Key Reinstallation Attacks: Breaking WPA2 by forcing nonce reuse'
03 Nov 2017
b'HackerOne'
disclosed a bug submitted by
b'exadmin'
b'Private partial disclosure of h1 infrastructure '
03 Nov 2017
b'Twitter'
disclosed a bug submitted by
b'yipman'
b'[CRITICAL] Full account takeover using CSRF'
03 Nov 2017
b'Twitter'
disclosed a bug submitted by
b'eidelweiss'
b'Unauthorized Access to Protected Tweets via niche.co API'
02 Nov 2017
b'Twitter'
disclosed a bug submitted by
b'cornerpirate'
b"OS Command Execution on User's PC via CSV Injection"
02 Nov 2017
b'Gratipay'
disclosed a bug submitted by
b'edio'
b'Saying goodbye to HackerOne and Gratipay.'
02 Nov 2017
1
...
496
497
498
499
500
...
738
BY DENIS WERNER - @NOBBD -
IMPRESSUM