hacking: security in practice
Microsoft scammed me out of a teams bug bounty
I reported my first major bug in teams last month.
Basically if you were an employee that had your account disabled or your left the company you would still receive notifications of messages to rooms you were previously a part of.
This is because the notifications socket had no authentication believe it or not and once your signed in it did not do any of its own authentication or even time out.
I've been aware of sensitive and confidential information because of this issue and I consider it severe. Its been around for at least a few years so I reported it to Microsoft through the correct channels.
Instead of rewarding a bounty or even acknowledging my report it was closed with *not enough information to reproduce' but then fixed within a few days. My followup messages were ignored and quite frankly the whole experience has left a bitter taste in my mouth.
I'm not sure what if anything I can do about this but I just wanted to warn others that it may not be worth submitting this kind of information to Microsoft. I'm certainly not going to again.
submitted by /u/managedheap84
[link] [comments]
Microsoft scammed me out of a teams bug bounty
I reported my first major bug in teams last month.
Basically if you were an employee that had your account disabled or your left the company you would still receive notifications of messages to rooms you were previously a part of.
This is because the notifications socket had no authentication believe it or not and once your signed in it did not do any of its own authentication or even time out.
I've been aware of sensitive and confidential information because of this issue and I consider it severe. Its been around for at least a few years so I reported it to Microsoft through the correct channels.
Instead of rewarding a bounty or even acknowledging my report it was closed with *not enough information to reproduce' but then fixed within a few days. My followup messages were ignored and quite frankly the whole experience has left a bitter taste in my mouth.
I'm not sure what if anything I can do about this but I just wanted to warn others that it may not be worth submitting this kind of information to Microsoft. I'm certainly not going to again.
submitted by /u/managedheap84
[link] [comments]
reddit
Microsoft scammed me out of a teams bug bounty
I reported my first major bug in teams last month. Basically if you were an employee that had your account disabled or your left the company you...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Hack Facebook and other Social Media account and also protect them :)
https://cdn-images-1.medium.com/max/800/1*wIXRUf5zCXedyo4BNuit-Q.png
Now you can Hack any desired Facebook account also any desired social media account….. and also protect them :)
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Hack Facebook and other Social Media account and also protect them :)
https://cdn-images-1.medium.com/max/800/1*wIXRUf5zCXedyo4BNuit-Q.png
Now you can Hack any desired Facebook account also any desired social media account….. and also protect them :)
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Hack Facebook and other Social Media account and also protect them :)
Now you can Hack any desired Facebook account also any desired social media account….. and also protect them :)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Copmuter? Computer Full Explaination.
https://cdn-images-1.medium.com/max/600/0*qqfB0KIJ0OsK_d-G.jpg
What is Copmuter? Computer Full Explaination. by Minhaj Times.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is Copmuter? Computer Full Explaination.
https://cdn-images-1.medium.com/max/600/0*qqfB0KIJ0OsK_d-G.jpg
What is Copmuter? Computer Full Explaination. by Minhaj Times.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is Copmuter? Computer Full Explaination.
What is Copmuter? Computer Full Explaination. by Minhaj Times.
Dynamic payload generation with mingw
https://www.reddit.com/r/redteamsec/comments/nsxfop/dynamic_payload_generation_with_mingw/
submitted by /u/cysboy (https://www.reddit.com/user/cysboy)
[link] (https://passthehashbrowns.github.io/dynamic-payload-generation-with-mingw) [comments] (https://www.reddit.com/r/redteamsec/comments/nsxfop/dynamic_payload_generation_with_mingw/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/nsxfop/dynamic_payload_generation_with_mingw/
submitted by /u/cysboy (https://www.reddit.com/user/cysboy)
[link] (https://passthehashbrowns.github.io/dynamic-payload-generation-with-mingw) [comments] (https://www.reddit.com/r/redteamsec/comments/nsxfop/dynamic_payload_generation_with_mingw/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Dynamic payload generation with mingw
Posted in r/redteamsec by u/cysboy • 29 points and 1 comment
Hacker Spotlight: hunt4p1zza & pmnh
Continuing our spotlight series, featuring two of our bug bounty winners from our April promo event.Continue reading on Uber Privacy & Security »
Read more...
Continuing our spotlight series, featuring two of our bug bounty winners from our April promo event.Continue reading on Uber Privacy & Security »
Read more...
Trending repositories on GitHub today · GitHub
fabionoth / awesome-cyber-security
A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.
Language: unknown
Star: 512
Fork: 113
___________________________
@hacking_Attack
@Hacking_Video
fabionoth / awesome-cyber-security
A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.
Language: unknown
Star: 512
Fork: 113
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - fabionoth/awesome-cyber-security: A collection of awesome software, libraries, documents, books, resources and cools stuffs…
A collection of awesome software, libraries, documents, books, resources and cools stuffs about security. - fabionoth/awesome-cyber-security
Hacking Articles Tips Tricks Videos Tutorials pinned «Trending repositories on GitHub today · GitHub fabionoth / awesome-cyber-security A collection of awesome software, libraries, documents, books, resources and cools stuffs about security. Language: unknown Star: 512 Fork: 113 ___________________________…»
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Lightning -> AUX hack cables?
Hey hacking. I went to purchase an adapter for lightning -> 3.5mm AUX so I can use my headphones as my ~official one broke.
The store had 3rd party ones but I don’t really care about having apple branded accessories/they’re a rip off so I picked one up, no problem.
Just before I paid, the guy wanted to ‘show me how it works’. I was hesitant because surely....it should just plug in. I was a bit stupid and didn’t immediately say no, put in my code and handed my phone over for him to ‘show’ me. Apparently the one I picked pops up with a prompt to ‘connect’ to it the first time you use it, so he wanted to make sure I pressed that.
Menu that came up wasn’t like any apple menu I’d usually use to connect to an accessory - this was a white pop up at the bottom of my screen
I recently saw the super cool O.M.G. Cable and I guess it’s made me a little paranoid.
Does anyone know of similar exploits floating around in third party accessories/their software, or is this just another case of third parties having to work around Apple?
I guess if it was attack hardware he probably wouldn’t be selling it but I just want some reassurance lol :L
submitted by /u/drugCrazedSexDwarf
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Lightning -> AUX hack cables?
Hey hacking. I went to purchase an adapter for lightning -> 3.5mm AUX so I can use my headphones as my ~official one broke.
The store had 3rd party ones but I don’t really care about having apple branded accessories/they’re a rip off so I picked one up, no problem.
Just before I paid, the guy wanted to ‘show me how it works’. I was hesitant because surely....it should just plug in. I was a bit stupid and didn’t immediately say no, put in my code and handed my phone over for him to ‘show’ me. Apparently the one I picked pops up with a prompt to ‘connect’ to it the first time you use it, so he wanted to make sure I pressed that.
Menu that came up wasn’t like any apple menu I’d usually use to connect to an accessory - this was a white pop up at the bottom of my screen
I recently saw the super cool O.M.G. Cable and I guess it’s made me a little paranoid.
Does anyone know of similar exploits floating around in third party accessories/their software, or is this just another case of third parties having to work around Apple?
I guess if it was attack hardware he probably wouldn’t be selling it but I just want some reassurance lol :L
submitted by /u/drugCrazedSexDwarf
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Lightning -> AUX hack cables?
Hey hacking. I went to purchase an adapter for lightning -> 3.5mm AUX so I can use my headphones as my ~official one broke. The store had 3rd...
Qilin Mainnet V1 Bug Bounty
https://qilinprotocol.medium.com/qilin-mainnet-v1-bug-bounty-964ba974eceb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://qilinprotocol.medium.com/qilin-mainnet-v1-bug-bounty-964ba974eceb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Qilin Mainnet V1 Bug Bounty
Following the mainnet launch on June 4th, Qilin initiates its long-term Bug Bounty Program with the Qilin NFT reward. We invite the public…
Following the mainnet launch on June 4th, Qilin initiates its long-term Bug Bounty Program with the Qilin NFT reward. We invite the public…Continue reading on Medium » (https://qilinprotocol.medium.com/qilin-mainnet-v1-bug-bounty-964ba974eceb?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Qilin Mainnet V1 Bug Bounty
Following the mainnet launch on June 4th, Qilin initiates its long-term Bug Bounty Program with the Qilin NFT reward. We invite the public…
Is Coding really Essential for Hacking: All queries answered
https://anonyethical3067.medium.com/is-coding-really-essential-for-hacking-all-queries-answered-5273aafd6433?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://anonyethical3067.medium.com/is-coding-really-essential-for-hacking-all-queries-answered-5273aafd6433?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Is Coding really Essential for Hacking: All queries answered
Hey Cyberpunks, I hope you are doing good. So I imagine, if you are here than you definitely want to excel in the field of Hacking. Again…
Hey Cyberpunks, I hope you are doing good. So I imagine, if you are here than you definitely want to excel in the field of Hacking. Again…Continue reading on Medium » (https://anonyethical3067.medium.com/is-coding-really-essential-for-hacking-all-queries-answered-5273aafd6433?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Is Coding really Essential for Hacking: All queries answered
Hey Cyberpunks, I hope you are doing good. So I imagine, if you are here than you definitely want to excel in the field of Hacking. Again…
Introduction
https://bountyget.medium.com/introduction-94b25aa2f8e6?source=rss------bug_bounty-5
HTTP Cookies and Sessions:Continue reading on Medium » (https://bountyget.medium.com/introduction-94b25aa2f8e6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://bountyget.medium.com/introduction-94b25aa2f8e6?source=rss------bug_bounty-5
HTTP Cookies and Sessions:Continue reading on Medium » (https://bountyget.medium.com/introduction-94b25aa2f8e6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Introduction
HTTP Cookies and Sessions:
Is Coding really Essential for Hacking: All queries answered
Hey Cyberpunks, I hope you are doing good. So I imagine, if you are here than you definitely want to excel in the field of Hacking. Again…Continue reading on Medium »
Read more...
Hey Cyberpunks, I hope you are doing good. So I imagine, if you are here than you definitely want to excel in the field of Hacking. Again…Continue reading on Medium »
Read more...
How Github recon help me to find NINE FULL SSRF Vulnerability with AWS metadata access
Hi, everyoneContinue reading on Medium »
Read more...
Hi, everyoneContinue reading on Medium »
Read more...