For #CyberSecMonth, we're proud to collaborate with industry-leading organizations like @GlobalCyberAlln, @StaySafeOnline & @Hacker0x01 to spread cybersecurity awareness, education & opportunity. Learn more here: https://t.co/FVRw8PC7f1
You can now scan for #react2shell in @Burp_Suite. To enable, install the Extensibility Helper bapp, go to the bambda tab and search for react2shell. Shout-out to @assetnote for sharing a reliable detection technique!
Congrats🇻🇳squad's good win with 2nd highest score in the 1/8 finals of the #AmbassadorWorldCup, secure a spot in the Elite Eight round at Prague, 🇨🇿!
🔥Flysec has a great hacking experience in AWC 1/8 finals being in Top 1 of Report Leaderboard!
Fighting for semi-final spot!
TikTok has a private program where they mention that:
"Private posts and .... is usually high-critical."
Yes, initially, I reported this issue through that program. After they reviewed it, they transferred my report to the main program (TikTok) and downgraded it to medium.
I was able to view all videos of any private account on TikTok.
In this report, the Confidentiality level is rated as LOW.
The reason provided by the TikTok and H1 mediation team:
"The attacker cannot guarantee that every video they steal contains sensitive information."
I discovered an endpoint that allows retrieving all videos from a private TikTok user, and he consider the confidentiality impact to be Low.
#bugbounty#hackerone
3/
Compared to the report that earned the $8,000 reward, the private video disclosure issue was more severe. However, they managed to downgrade it to a medium severity level and fixed it within 24 hours.
TikTok has a private program. If you’re part of this program, It can be seen in the program’s policy that video disclosure is considered Critical. I initially reported the issue there, but they transferred it to their public program and downgraded the severity to Medium.
For three consecutive years, I’ve held a position as one of TikTok’s top hackers – I’m proud to contribute to securing the platform and ensuring safety for its global community of users. Thanks @tiktok_us@Hacker0x01#togetherwehitharder
https://t.co/xFocBz6qEq