“How I found the most critical bug in live bug bounty event?” by Lakshay https://link.medium.com/CwfZBZO2I3
Medium
How I found the most critical bug in live bug bounty event?
Hey Folks! Hope you guys are doing great.
“Password Reset Vulnerability — Full Account takeover (Insecure Direct Object Reference)” by Muhammad Asim Shahzad https://link.medium.com/d6BPOQZ2I3
“Two-factor authentication security testing and possible bypasses” by Max https://link.medium.com/vWnWo4H6A3
Medium
Two-factor authentication security testing and possible bypasses
Before I began to comprehend the complex science of information security, it seemed to me that Two-Factor Authentication is a guaranteed…
Dropbox bug bounty program has paid out over $1,000,000
https://blogs.dropbox.com/tech/2020/02/dropbox-bug-bounty-program-has-paid-out-over-1000000/
https://blogs.dropbox.com/tech/2020/02/dropbox-bug-bounty-program-has-paid-out-over-1000000/
Forwarded from h1disclosebot
GitHub Security Lab disclosed a bug submitted by calderpwn: https://t.co/kJySKZdV0Z - Bounty: $1,000 #hackerone… https://t.co/x9GJt0F42A
HackerOne
GitHub Security Lab disclosed on HackerOne: CodeQL query to detect...
Report created by importer
WebSocket attacks
1. https://t.co/1V2XJnYsrc
2. https://t.co/jbIZKoIflw
3. https://t.co/Fg7uUwd7YB
4. https://t.co/jOVTIFWUEk
5. https://t.co/iiVV2uzm0J
6. https://t.co/iiVV2uzm0J
7. https://t.co/iiVV2uzm0J
8. https://t.co/nRqwcFe4zX
#bugbounty #bugbountytips
1. https://t.co/1V2XJnYsrc
2. https://t.co/jbIZKoIflw
3. https://t.co/Fg7uUwd7YB
4. https://t.co/jOVTIFWUEk
5. https://t.co/iiVV2uzm0J
6. https://t.co/iiVV2uzm0J
7. https://t.co/iiVV2uzm0J
8. https://t.co/nRqwcFe4zX
#bugbounty #bugbountytips
footstep.ninja
cat ~/footstep.ninja/blog.txt
The HTML5 Herald
OK Google: bypass the authentication! https://techblog.mediaservice.net/2020/01/ok-google-bypass-the-authentication/