@Vinootana@elonmusk@RupertLowe10 Don't spit your venom against Pakistan coz you're an Indian. Get out of the negative thinking and appreciate what good is happening anywhere in the world.
@krishnsec In this way, reputation will be built for genuine hackers. The system should then recommend triage team the hackers to give priority in assessments while the others would wait longer due to blind AI assisted reporting history or habit.
@Bugcrowd@intigriti@yeswehack
@krishnsec Platforms should introduce reputation system to score hacker reputation i.e. valid finding (or even duplicate one without AI assisted reporting) should give points to hacker (separate from the system of vulnerability acceptance reward points) and penalize for the opposite.
Thank you @Bugcrowd. Just earned a bounty for sensitive data disclosure through browser's local storage 💚
Sensitivity of data decides whether a program would accept it. I've received the comments "Great find. Thank you!"
🙂
#bugbounty#cybersecurity#appsec
⚠️ Giveaway time! ⚠️ 👇
📢 Our new course "Attacking AI" will be Feb 27-28!
This two-day course equips security professionals with the tools and methodologies to identify vulnerabilities in AI systems. It's gonna be a BANGER.
Syllabus: https://t.co/cY9vcI7Z5y
We are giving away two seats this week!
⁉️How to enter the giveaway:
♻️ Repost this post = 2 Entries
🗣️ Reply = 1 Entry
❤️ Like = 1 Entry
AL HAMD U LILLAH
Research @Bugcrowd ... Finding a valid issue that got rewarded. It's good to be back and starting with some success! 💚
Downgraded privilege from admin to normal, some actions could still be performed.
#bugbounty#cybersecurity#ethicalhacking#bugbountytips
@0xm1racle If the application enables 2FA with manually configuring the old key (key is old when you disabled previous 2FA which had been configured with that key), then I believe it's a bug with a similar kind of impact.
New writeup after a long time. I hope that it would be helpful especially for new bug hunters and pen testers!
#cybersecurity#ethicalhacking#bugbounty
https://t.co/pciaLFfOaM
@bhx1tn Yes. Disable 2FA (note down the secret or QR code while configuring it), then enable 2FA again. You should receive a different secret i.e. QR code now for configuration. If it is the same as the previous one, it's vulnerable.