How I was able to read any message on Discord without "VIEW_CHANNEL" or "READ_MESSAGE_HISTORY" permissions.
Simple vulnerability but a nice one!
https://t.co/Sv13KcfqLa
#security#discord#bugbounty
@discord's bug bounty is great, I love how my report for reading any message on the platform only got a high, while other issues with such high complexity (where you will never be able to pull it off) got marked as critical
Tried out @useblacksmith from @theo suggesting it, only to be given a invoice with no warning I went over the free tier besides a single email saying I was at 80% usage. I don't even got billing info setup idk why it was allowed to go past free limits fuck me for trying it out ig
@cursor_ai why does setting custom openai keys still stop composer from being used. It's stupid and annoying, I hate having to switch on / off openai keys.
Gemini and Anthropic keys work perfectly fine
@cursor_ai PLEASE fix the issue where sometimes in chat, messages I send are "ghost" messages where they exist in the ui but don't exist in the chat. Instead it causes the model to repeat / continue based on the previous message
๐จโผ๏ธDiscord leaked user IDs with ban reasons to the EU DSA Transparency Database until 2025.
Discord supplied the IDs by mistake. The EU hosted it all.
The irony? The DSA is a regulation designed to protect users.
We're building a Slack alternative called Fractura! Early access is opening soon. First 100 teams that join the waitlist will get 50% off for LIFE.
If you run a startup or remote team and are tired of slack, sign up for the waitlist.
https://t.co/HmGoWVzN6l
#slack#alternative
honestly, @cursor_ai's bug bot is great compared to coderabbit, only issues I have with it are:
1) No "Prompt For AI" instead its hidden in "Fix with Cursor / On Web"
2) Seemingly no way to tell it to ignore something, so it'll keep bringing it up again and again.
How I was able to read any message on Discord without "VIEW_CHANNEL" or "READ_MESSAGE_HISTORY" permissions.
Simple vulnerability but a nice one!
https://t.co/Sv13KcfqLa
#security#discord#bugbounty
@TehAngryXeno@ghostympa "buggy af atm" and "best alternative" should not be in the same sentence. It's also been buggy for years its hardly had any development. Fluxer is generally the better alternative
@fox_god_is_here@RealSchlep@discord I'm not on the best terms with discord regarding the site. Sharing the ids would likely not end well for me regarding my account.
@Shyfire_Kya@RealSchlep@discord The highest ban account is the ID of the deleted Discord User ID (456226577798135808) so showing it would make people think somebody actually had that many actions when that was just not the case.