Last year, @Hxzeroone challenged himself to earn $100k in bounties by his 18th birthday. We sat down with him to talk about his Bug Bounty Journey, tips for staying motivated, and hitting his next Bugcrowd milestone! 🎉
https://t.co/heRdLLWFIf
@ldionmarcil@sml555_@codecancare Yes , we had reported issues to such platforms and got them fixed where their connectors and recipes were directly vulnerable.
This has been a recent implementation in Google sheets prior to that there wasn’t any warning , it would auto-run once they were implemented.
Also to be noted , if the formulaes are allowed once ,they are not asked to be accepted again meaning an sheet that has previously added their own formuales and is ingesting data from attacker supplied sources would still be vulnerable.
Apart from that the same can be achieved on Microsoft Excel.
I had a great time at @Hacker0x01's H1-4420 in London. Was great working with @TomAnthonySEO, @Hxzeroone, @codecancare and @seanyeoh! This event also produced this tool: https://t.co/MOuK57Hwh1 which led to about $26k worth of bounties at this event.
Who is Hx01? 👤
September's Researcher Spotlight with 8+ years of experience hacking!
Check out this impressive #bugbounty journey below! 👣
#BugBountyTips#ItTakesACrowd
https://t.co/pK5SYPVRXx
I and @Hxzeroone somehow broke the internet this week. A total of approximately 200 reports sent so far across #Bugbounty platforms for this 0day. All the giants are affected. I mean it.
It's finally live - I'm sorry for the time this took!
The workshop I gave at @THREAT_CON is now live on Udemy for a discounted price. The price will go back to $149 at the end of the week . More details to follow.
https://t.co/7LoaJOwhzH
Congrats @Hxzeroone for reaching an ambitious goal! 👏
With the amazing collaboration and efforts (not to mention memes 🔥) we saw in the #TeamHunt2021, we’re honored to be a part of this milestone! Great work! 😎