@yeswehack Is implementing a credit system to prevent sloppy submissions. Have to use credits to be able to submit to a program. Valid and impactful reports generate more credits. This could be great. Roll it out!
Just got a reward for a vulnerability submitted on @yeswehack -- Unrestricted Upload of File with Dangerous Type (CWE-434). https://t.co/lSCikFI9Cd #YesWeRHackers
Just got a reward for a vulnerability submitted on @yeswehack -- Unrestricted Upload of File with Dangerous Type (CWE-434). https://t.co/lSCikFI9Cd #YesWeRHackers
Just got a reward for a vulnerability submitted on @yeswehack -- Insecure Direct Object Reference (IDOR) (CWE-639). https://t.co/lSCikFI9Cd #YesWeRHackers
Just got a reward for a high vulnerability submitted on @yeswehack -- Insecure Storage of Sensitive Information (CWE-922). https://t.co/lSCikFI9Cd #YesWeRHackers
Just got a reward for a vulnerability submitted on @yeswehack -- Insecure Direct Object Reference (IDOR) (CWE-639). https://t.co/lSCikFI9Cd #YesWeRHackers
@RitikShilp80441@yeswehack That one was really quick, but it was actually an insecure design / IDOC issue. Triage decided to call it IDOR for some reason.
Just got a reward for a vulnerability submitted on @yeswehack -- Insecure Direct Object Reference (IDOR) (CWE-639). https://t.co/lSCikFI9Cd #YesWeRHackers
Just got a reward for a high vulnerability submitted on @yeswehack -- Server-Side Request Forgery (SSRF) (CWE-918). https://t.co/lSCikFI9Cd #YesWeRHackers
Just got a reward for a vulnerability submitted on @yeswehack -- Violation of Secure Design Principles (CWE-657). https://t.co/lSCikFI9Cd #YesWeRHackers
Just got a reward for a vulnerability submitted on @yeswehack -- Cross-site Scripting (XSS) - Reflected (CWE-79). https://t.co/lSCikFI9Cd #YesWeRHackers