MOST BUGS I find aren't clever exploits. they're "the docs guarantee X, the code never enforces X." pick any security boundary, read the spec, then read the implementation. the gap between them is your report. source review > black-box recon
#bugbounty #intigriti #bug #hacker
Logic Bypass + Missing Range Checks = $750. ๐ธ
Reported an Unauthenticated Heartbeat Spoofing vulnerability that allowed for remote host manipulation and alert suppression. The team was kind enough to throw in a bonus for the detailed RCA
Always rewarding to see deep dives pay off.
#BugBounty #SecurityResearch #DevSecOps #HackerOne #InfoSec
@pdiscoveryio paid me xxx$ to fix a hang in tlsx that was choking scans on 30k+ targets handshakes with no timeouts, workers stuck on context.Background(), sequential cipher enum.
fix โ 30k in 2m31s, zero hangs. merged upstream, $xxx bounty
#opensource#golang
17 year old , got paid $1,500 to crash a popular monitoring agent with one packet. unauth remote memory exhaustion, got a cve too on my name
#bugbounty#infosec#hackerone
Hostel warden Sunil Kumar (aka Mario) was caught on camera stealing from a studentโs room during exams. Heโs seen rummaging through cupboards and furniture, labeled โChor warden.โ
Viral video from ABES Engineering College, Ghaziabad:
Phenomenal is an understatement. Respect is earned and few are more worthy of universal industry wide respect than @AJStylesOrg. Thank you AJ for all youโve done for wrestling. From anyone whoโs seen you and those lucky enough to share canvas with you.