I have a blasting 2020 with doing #bugbounty on @gitlab Hackerone. I will be publishing write-ups of some findings that may sound interesting to people here:
https://t.co/qCC9F41NZe
I’ve hacked every major crypto exchange. Reported critical vulnerabilities that would make the news if we disclosed.
If you are scared of holding your crypto in cold storage because of the Coldcard hack and is thinking you are better off holding in an exchange, I can tell you one thing with certainty.
Do not trust Binance. You WILL lose your funds.
This was done with zero AI as well, the poc script is the only thing generated out of it, im very disappointed with the decision that they are making and the lack of comms
Me and @ledz1996 are still trying to communicate with the @coinbase and @JLunglhofer team regarding an extreme severity vulnerability and still getting ghosted and no replies.
I used to praise this program, and always recommended to every researcher. It is completely changed. Seems like we will likely have to go for the disclosure route unfortunately.
Trying to make last ditch effort to have some kind of dialog with them though.
Sad
Me and @ledz1996 are still trying to communicate with the @coinbase and @JLunglhofer team regarding an extreme severity vulnerability and still getting ghosted and no replies.
I used to praise this program, and always recommended to every researcher. It is completely changed. Seems like we will likely have to go for the disclosure route unfortunately.
Trying to make last ditch effort to have some kind of dialog with them though.
Sad
I may be the lucky one since that was the only time that I was truly disappointed in a program and how they react. Despite all that, the trust is not lost in some programs in web2/web3. Most of them are old, battletested but you won't be disappointed when you spend time one them
WE just had the worst experience on one program for one of the (if not) the biggest exchange in the world. A lot of gas lightings, downplayings, legal threats.But I still believe in the bug bounty world, it changed my life. there are still some trustworthy programs (OKX, GitLab)
Our #H165 live hacking event with @tiktok_us and @okx in Singapore was a big success! It's time to celebrate this year's winners. Here we go... 🥁
For TikTok:
Eliminator: avishai
Exterminator: kevin_mizu, shubs, hashkitten
Vigilante: m4II0K
For OKX:
Eliminator: hackerontwowheels, ledz1996
Exterminator: corraldev
Vigilante: corraldev
Overall:
Community choice: nadino
Best collab: kevin_mizu, shubs, hashkitten & hackerontwowheels, ledz1996
Most valuable hacker: corraldev
Thanks @Hacker0x01 and @okx team for an amazing LHE and warm reception.
#h165 was awesome, really cool meeting everyone.
Leaving Singapore 2nd place 🥈 , and taking these cuties home.
Won Best Collaboration and Eliminator rewards with my buddy @ledz1996 .
God is good.
@S1r1u5_ And it sometime requires your intuition and instinct thinking (sorry i dont know how to phrase the word correctly) that something LLM is lacking of but you can use it to accel yourself in some boring works to bring out your creativity
@fchralph@antoniogm I would lol, western standards is so fked up lmao try going there please, open ur eyes, jesus christ.
What youve wrote is basically said "its ok to steal from others"
The xz fiasco has shown how a dependence on unpaid volunteers can cause major problems. Trillion dollar corporations expect free and urgent support from volunteers.
@Microsoft@MicrosoftTeams posted on a bug tracker full of volunteers that their issue is "high priority"
@tdietterich Almost the entire IT infrastructure globally relies on OpenSSH being free of remote vulnerabilities. Hundreds of people have read the code carefully, trying to find new flaws. No closed-source software no matter the amount of third party testing would ever reach that level of ...
@cyb3rops He did that so that 100 engineers from 100 orgs dont have to fuking reverse the god damn patch, thats basically half of the job done, be grateful of what you got and dont be an ass, wont you?
if you found an SSRF in an application running on Kunernetes (AWS EKS), the default IAM profile for the node has "eks:DescribeCluster" privileges.
With these privileges, you have access to the "aws eks update-config" command which gives access to cluster certificates.