@vxunderground i stopped researching github security a while ago due to bad treatment, but https://t.co/O30TVvqkyq was one of my favorite targets. it had so many bugs. would love to talk more about them but theyre holding tens of thousands of advertised bounties hostage in mediation cases π₯²
@frostb1ten@msftsecresponse@Microsoft best part still was when i made a disgruntled post without details & suddenly they were on a first name basis with me despite never having used that name in a professional context because the nice people at M$ even stalk your twitter when they scam you π₯°
@frostb1ten@msftsecresponse never got a single cent from them, in fact even made a slight loss. i was young and stupid. seasoned researchers know that the only reasonable way to handle @Microsoft disclosures is full disclosure. ill never forgive them for even demanding a meeting while i was on vacation...
hey, this vuln seems familiar!
this has actually been a thing for over two years now.
how do i know? its been almost two years since i reported the exact same vulnerability to twitter's hackerone π
twitter's security & bug bounty program is laughably bad, a thread
@mugundhanbalaji@HaifeiLi they're often the same! i found a fun one recently that allowed running an arbitrary file without args, and exploited it by getting a username leak, opening the default web browser to a page with content-disposition, and then called open(`C:/Users/${user}/Downloads/pwn.exe`) lol
@rez0__ as someone with an embarrassingly high number of reports to them: theyre massive scammers, that number checks out. and even if you do get paid, they straight up lie in their bounty table and pay 10% of what they promise despite agreeing on the vuln type after waiting months π«
@hrkrshnn dont report shit to the github bug bounty, they're massive scammers. they openly break their bounty table promises and regularly close issues explicitly listed in the scope with bounties as informative, and they stealth fix those
@meowkoteeq i love the gen1 steam controller dearly but that thing did NOT have swappable batteries, once they were in they were never coming out again LMFAO