@Zaddyzaddy@Bugcrowd@BugBunny_ai Last month I submitted 2 source code vulns and after 27 days they replied me that it's not reproducible and deducted 2 points
I am also the owner of an active Discord server with approximately 2,000 members. Because I cannot access my account, I am unable to manage the community or transfer ownership. I would appreciate assistance restoring access or guidance on how ownership can be recovered.
@discord@discord_support
My account was suspended and I was told to submit an appeal through the Discord app. However, I cannot access the account because Discord is rejecting my Google Authenticator 2FA codes as invalid.
I've opened support tickets and keep receiving automated responses directing me back to the in-app appeal process, which I cannot access.
Ticket: #67080037
Could someone please review this manually?
@hamidonsolo@itsmeNxSTY@0xHun73r@ide9x Maybe I saw your tweet earlier or someone else's, i honestly don't know anymore 😕 I'm deleting this comment before I embarrass myself further
@itsmeNxSTY@0xHun73r@ide9x@hamidonsolo Bro I actually tried finding that tweet again in my feed but failed 😭
I was even thinking of deleting my comment, but then you replied
@Zaddyzaddy@oppo@Hacker0x01 Can confirm this from personal experience. A while ago I reported an information disclosure issue that exposed confidential documents and internal deal-related data. The report was marked as N/A, but the issue still got patched afterward. That honestly says enough.
Found a Pre-Account Takeover (Pre-Hijacking) via missing email verification + OAuth linking → leads to 0-click account takeover.
Marked duplicate but still got +5 pts
Duplicates = hunting in the right spot
#BugBounty#AppSec
Hey @coffinxp7 quick q — I reported a punycode email trick (0-click ATO) to a self-hosted program but they replied it’s invalid, saying SMTP shows reset mail goes to [email protected].[chars].oastify.com (victim) not my homoglyph gmàil. They call it “no impact”. Thoughts?