@ZenoEleatis@vkrj_ Yeah I agree. fwiw tho ms said they didn’t disclose the vulns prior to dropping them. So if that’s true, there’s no evidence they could provide to begin with. Just keep that in mind. No one thinks it’s weird nightmare hasn’t provided proof of… anything? Hmmmm
@deadvolvo@ChaoticEclipse0 Yeah I mean kinda weird eclipse hasn’t posted any receipts and claims they can’t because ms has “chains” around their hands? But they can continue to drop six 0days? Doesn’t make sense at all imo
@ZenoEleatis@vkrj_ Why doesn’t nightmare post any evidence about… any of this? They can’t because ms had “chains” around their hands but they can post six 0days? That doesn’t make any sense at all dude
@arekfurt Just release the details. Whenever they say something is lower than important you’re allowed to disclose it, they even tell you that. Sometimes after you disclose it they increase severity and pay you bounty 😂
@EvilRabbitSec Eh idk man everyone with a brain cell knew that 1st post wasn’t about jailing researchers for posting 0days. Ppl have done that forever. M$ may be dumb af but they know that wouldn’t happen. Smtg else is going on here, it all reeks of bs
@gcvftw@ghostinthecable Eclipse needs to drop some proof with what actually happened bro. There’s none. Ms said they didn’t report anything. Eclipse can drop 6 0days but no proof cuz ms has “chains” on their hands? That doesn’t make any sense at all. Like, none.
@ghostinthecable Yeah but how do we know that even happened. Eclipse can drop 6 0days, with more inc, but can’t say what happened because “ms has chains on their hands” or w/e? Idk man my radar is going off because that doesn’t make any sense at all… something stinks with this story.
@scriptjunkie1 Agree, the thinly veiled threat is fucked. I’m not sure it’s targeted at ppl that drop 0days tho ppl do that all the time. Smtg else is happening and eclipse had/has a part in it or they’d be posting proof, not 0days while saying “ms has chains on their hands” smells like bs
@RossMichaels328@spaghetticoffee@Knubbeh@Microsoft Incorrect. You can make a free email, and submit a report. I’ve done this several times on submissions that have not been paid, and in some cases received bounty. The portal is completely anonymous. It’s clear you’ve never submitted a bug through it.
@EvilRabbitSec Very obviously why this isn’t about dropping 0days lol. Something else is going on here with nightmare, why can’t they provide the receipts? Even a ss? No one thinks that’s sus ?they can drop 6 0days but can’t say what happ because ms has “chains around their hands”? Hmmmm suuure
@waltuuuhr@AllenMullen@politicalmath sorry man, this happens to all of us at some point. its part of the process and just how it goes sometimes. Someone else found it first. if they start paying researchers for every duplicate bug they get that would be ridiculous. move on, find another bug
@RossMichaels328@spaghetticoffee@Knubbeh@Microsoft nightmare claimed they were banned by msrc, one of the reasons they released the 0days to the public. It's a public, anonymous bug bounty, you literally cannot be banned from it. also exploitation of these bugs by nation states was only seen after public release
@Rabilidade@jonasLyk@the_secret_club so is this dude gonna show proof of his M$ correspondences or what. How can you be banned from a public, anonymous bug bounty?? just make a new email and resubmit, I've done that multiple times 😂😂