@0xblackbird found few PyPi internal packages, claimed them with classic PoC that extracts host, IP, path, and PyPi account and packages banned after 1 hour. Therefore no PoC and Informative.
DM if you have a workaround to not get banned :)
@hacker_@pxmme1337@d0rsky@kucoincom@HackenProof its frustrating but I now choose programs that have bounty ranges per severity basing it on the lowest side. If a company pays 200-500 for Medium, I expect no more than 200 for my report.
Making it a range its just a marketing strategy to make it appealing for more hackers :DD
@atomiczsec @God_1337_ endpoint was an UUID for each user and response contained email nd language info only? If so then we might have reported the same one:D