π¨ Critical Vulnerability
π¨ Critical Hardcoded IBM Cloud API Key in Admin JavaScript Allows Unauthorized IAM Token Generation (Cloud Account Compromise)
π Full writeup:
https://www.facebook.com/share/p/18JAevtdRq/?mibextid=wwXIfr
π¨ Critical Hardcoded IBM Cloud API Key in Admin JavaScript Allows Unauthorized IAM Token Generation (Cloud Account Compromise)
π Full writeup:
https://www.facebook.com/share/p/18JAevtdRq/?mibextid=wwXIfr
β€20π₯6
My First Accepted HackerOne Report: Finding Exposed API Keys Across 5 Targets:
https://medium.com/@ziadali200244/my-first-accepted-hackerone-report-finding-exposed-weglot-api-keys-across-5-targets-fb14ecda869b
https://medium.com/@ziadali200244/my-first-accepted-hackerone-report-finding-exposed-weglot-api-keys-across-5-targets-fb14ecda869b
Medium
My First Accepted HackerOne Report: Finding Exposed Weglot API Keys Across 5 Targets
Good evening everyone. This writeup is about my first report accepted on HackerOne and how I found the same issue on 5 different targets.
β€34π₯9
Self hosted +Bug bounty programsβ¬οΈ
*.cleeng.com
security@cleeng.com
βββββββββββββ
*.redsift.com
security@redsift.com
βββββββββββββ
*.plain.com
security@plain.com
βββββββββββββ
*.linkdm.com
support@linkdm.com
βββββββββββββ
*.ory.com
security@ory.com
βββββββββββββ
*. aquanow.com
bugbounty@aquanow.com
βββββββββββββ
https://github.com/swisscom/bugbounty
βββββββββββββ
https://www.spendesk.com/.well-known/security.txt
βββββββββββββ
https://help.spreaker.com/en/articles/5123644-bug-bounty-program
βββββββββββββ
https://www.fjdynamics.com/jp/bug-bounty-program
βββββββββββββ
https://www.klook.com/bugbounty
βββββββββββββ
https://gobright.com/responsible-disclosure-policy/
βββββββββββββ
https://www.make.com/en/bounty
βββββββββββββ
https://www.pubnub.com/bug-bounty-policy/
βββββββββββββ
https://help.doit.com/docs/vendor-information/bug-bounty-program
βββββββββββββ
https://www.lenskart.com/vulnerability-disclosure-policy
βββββββββββββ
https://www.talentlms.com/vulnerabilitypolicy
βββββββββββββ
https://whatbox.ca/policies/security
βββββββββββββ
*.perlego.com
security@perlego.com
βββββββββββββ
https://support.playerauctions.com/hc/en-us/articles/49330305602585-PlayerAuctions-Bug-Bounty-Program
*.cleeng.com
security@cleeng.com
βββββββββββββ
*.redsift.com
security@redsift.com
βββββββββββββ
*.plain.com
security@plain.com
βββββββββββββ
*.linkdm.com
support@linkdm.com
βββββββββββββ
*.ory.com
security@ory.com
βββββββββββββ
*. aquanow.com
bugbounty@aquanow.com
βββββββββββββ
https://github.com/swisscom/bugbounty
βββββββββββββ
https://www.spendesk.com/.well-known/security.txt
βββββββββββββ
https://help.spreaker.com/en/articles/5123644-bug-bounty-program
βββββββββββββ
https://www.fjdynamics.com/jp/bug-bounty-program
βββββββββββββ
https://www.klook.com/bugbounty
βββββββββββββ
https://gobright.com/responsible-disclosure-policy/
βββββββββββββ
https://www.make.com/en/bounty
βββββββββββββ
https://www.pubnub.com/bug-bounty-policy/
βββββββββββββ
https://help.doit.com/docs/vendor-information/bug-bounty-program
βββββββββββββ
https://www.lenskart.com/vulnerability-disclosure-policy
βββββββββββββ
https://www.talentlms.com/vulnerabilitypolicy
βββββββββββββ
https://whatbox.ca/policies/security
βββββββββββββ
*.perlego.com
security@perlego.com
βββββββββββββ
https://support.playerauctions.com/hc/en-us/articles/49330305602585-PlayerAuctions-Bug-Bounty-Program
β€22
Critical Exposure of Algolia Admin API Key in Client-Side JavaScript:
https://medium.com/@zx10a/critical-exposure-of-algolia-admin-api-key-in-client-side-javascript-c41cacb4aed6
https://medium.com/@zx10a/critical-exposure-of-algolia-admin-api-key-in-client-side-javascript-c41cacb4aed6
β€22π₯5π1
Official Channels β ForBugHunters
Stay connected and never miss the latest in bug hunting, cybersecurity insights, live hacking sessions, and exclusive learning content.
βΆοΈ YouTube
https://youtube.com/@forbughunters
π’ Telegram Channel
https://t.me/ForBugHunters
π¬ Telegram Community Chat
https://t.me/+jA2uqHEQ16cxOGVk
Join the community and level up your hacking skills.
Stay connected and never miss the latest in bug hunting, cybersecurity insights, live hacking sessions, and exclusive learning content.
βΆοΈ YouTube
https://youtube.com/@forbughunters
π’ Telegram Channel
https://t.me/ForBugHunters
π¬ Telegram Community Chat
https://t.me/+jA2uqHEQ16cxOGVk
Join the community and level up your hacking skills.
β€19π₯2
ForBugHunters pinned Β«Official Channels β ForBugHunters Stay connected and never miss the latest in bug hunting, cybersecurity insights, live hacking sessions, and exclusive learning content. βΆοΈ YouTube https://youtube.com/@forbughunters π’ Telegram Channel https://t.me/ForBugHuntersβ¦Β»