I was hyped when approaching the Elastic bug bounty program. My optimism hasn't gone away for the first half of the challenge. But unfortunately, in 100 hours I only submitted 1 valid bug and got $584. Check out the video to see why I think I failed
https://t.co/7y8xWlnnue
@perribus@gamozolabs What I've heard from some viewers is that it's somewhat therapeutic for them to see that others (streamers) make mistakes while coding and have to spend half of the stream debugging and scratching their heads.
So there seems to be value in publicly making mistakes in code ;)
This one hurt to watch, @Yogehi put a lot of work into his exploit, only for it to get shot down by Samsung a month before the contest
On the plus side, he got a really good blog post out of it!
We love to experiment new concept during @hack_lu we have 5 talks talking (and enjoying) failures. Those will be given tonight after lightning talks session. Thanks to @_saadk for the original idea. Thanks to @virtualabs@inbarraz@cvandeplas@rafi0t for the dive in cold waters.
Let's try something new and document a bit of a failure😅
I briefly fuzzed the Windows t2embed.dll library (handles EOT fonts in e.g. PPTs in PowerPoint) and didn't find any significant bugs. Has it been beaten to death by efforts like https://t.co/ar5j69DrPd? :)