> pay for 16 different certifications
> job is sending phishing emails and read coworkers slack messages
cybersecurity has to be the worst branch of computer science
We accidentally got access to every Academy Award nominee's home address and phone number.
Before last year's Oscars Ceremony, together with @iangcarroll and @samwcyo, we found a way to leak every nominee's PII, including phone numbers and home addresses of the biggest actors around the world - from @ladygaga to @JaredLeto.
We were interested in the security of award ceremony shows, especially with the rise of @Kalshi and @Polymarket betting on winners. We wanted to check if it would be possible for an attacker to leak the winner before the official announcement.
While we didn't find evidence of that, we did notice that two of the Academy Awards' primary services had their APIs publicly facing without any authentication.
One offered general information about the ceremony, and the other allowed nominees to sign up and vote.
The first one - https://t.co/ddhQbVsYVd - allowed us to fetch every transaction made to sign up as a nominee for the Academy Awards, including member IDs and last four digits of credit cards.
With one request, we could get hundreds of contact IDs which could be chained with another API to correlate them to actual Hollywood actors via https://t.co/O0lrQQpXXR{ID}
Randomly skimming through the results, we saw they leaked full names, home addresses, phone numbers, email addresses of famous Hollywood stars.
We responsibly disclosed the findings to the Academy Awards on January 14th, which were promptly fixed.
Yay! I was awarded $1,000,000,000 on @Hacker0x01. With 5,000 reputation points earned from that report, I was able to access the list of all CIA agents, including the U.S. nuclear codes. I disagreed with them because the bounty was paid too low
0-100k in Bug Bounty with a 9-5 Job
Well, I'm happy to say my fourth bounty just got accepted this morning.
STATS:
Total Days Spent: 75
Total Time Spent: 517:03:39 HRS
Time Spent on Hunting: 244:51:50 HRS
Total Bugs: 11
Accepted: 4
Dupe: 2
NA: 5
Total Bounty: 4000$
@Rhynorater
I just pwned TheFrizz on @hackthebox_eu ! In 4 years, this is the first time I'm getting #Blood on a machine. Feel good!!! This was a great machine that requires careful enumeration. For now this also puts me in 1st in the season leaderboard #HackTheBox#htb#CyberSecurity
We are about to witness a real-world GPS spoofing attack.
GPS spoofing attack involves transmitting fake GPS signals to deceive a device's location. Using a HackRF, a software-defined radio tool, attackers can generate and transmit GPS signals.
https://t.co/eB7FsRbqYR