Found a validation-ordering flaw in Go's webp (VP8L) decoder: dimension check ran *after* a 1 GiB allocation instead of before.
Reported via Google OSS VRP, credited by the Go team in golang/go#80063.
Classified as hardening, not a vuln - clean catch ๐น
Just got a reward for a vulnerability submitted on @yeswehack - Insecure Direct Object Reference (IDOR) (CWE-639).
BINGO
https://t.co/pHaAQDWOiE
https://t.co/WxqtROjGf8
https://t.co/jL0RnQY46i #YesWeRHackers
๐ Just beat the "Dojo #51 - DeadBolt" challenge on @YesWeHack!
Think you can match my skills? ๐
https://t.co/1V8A4orA42
#YesWeHack#ChallengeAccepted
BINGO! Found a hole. Reported it. Got rewarded. That's the cycle. ๐ Just received a bug bounty payout from @yeswehack for an Improper Access Control finding (CWE-284). Keep hunting. ๐
Thanks...
https://t.co/jL0RnQY46i #YesWeRHackers#herdiyanitdev#indonesia#CTO
๐ NASA mission completed โ
Vulnerability report resolved through the Bugcrowd platform for NASA.
Grateful to contribute to the security of such a critical organization.
Hunting responsibly, one report at a time. @Bugcrowd#Herdiyanitdev#Indonesia#NASA#Bugcrowd#CTO
Midnight commands and monitor glows. Building something big. ๐ฅ @herdiyanitdev #SysAdmin#TechLife"
"Books for knowledge, Gundam for spirit. Ready to code. ๐ป๐ค @herdiyanitdev #Engineer#Setup