@k_firsov@Hacker0x01 What actually are workers rights for these bug bounty platforms? Seems like the employer just takes value if they want it, otherwise, the employee is nothing to them.
@VolkisAU I suppose it's not validating for a port so the code above would succesfully block requests to http://localhost:3306 or https://localhost:3306 but not https://allowedlist:3306/ which if it were running, would allow an ssrf to reach mysql (although creds would be needed)
@JackRhysider@ProtonMail how did you figure out their server/s listening on port 25 or that the emails to a user goes through port 25? nmap scanned it? come to think of it i don't get email..