@Samm0uda Hackerone is not a safe place for all researchers and this is what we found out
Bugcrowd started learning from Hackerone the art of trading with the efforts of researchers
@Samm0uda there is also a lack of interest in many of the vulnerabilities or not taking it seriously and the scams that these programs do to the point that many researchers left working on these programs and did not give any importance because they became a waste of time ..
tried something new and wrote an LPE exploit for CVE-2021-3490, a bug in the Linux Kernel eBPF verifier. was fun and learned a lot - blog post + PoC coming soon. happy memorial day!
Anyone using ExifTool make sure to update to 12.24+ as CVE-2021-22204 can be triggered with a perfectly valid image (jpg, tiff, mp4 and many more) leading to arbitrary code execution!
@Samm0uda on these platforms, for exemple : the H1 platform. Even if you are scammed by a program and you used "H1 hacker mediation" then H1 will never help you even though you are right and they will tell you that you are wrong and they will give you reasons that have no meaning .
@Samm0uda Hackerone and Bugcrowd always exploit researchers, either you are a victim of a scam or they either give you $200 for a vuln whose original price is more than $ 10,000 ,