TumarOne platform (official channel)
266 subscribers
87 photos
30 links
Platform for rewarding the discovery of vulnerabilities in information systems and resources.

Platform: https://tumar.one
Support: @TumarOneSupportBot
Queries: info@tumar.one
Download Telegram
Hey researcher 👋
 
We'd like to invite you to KazHackStan - the biggest hacker conference in Central Asia, bringing together over 6,000 attendees, top security researchers, and leading experts in information security.
 
The Top 10 researchers of Tumar.One will be invited on stage at KazHackStan - where they will be awarded with merch and named awards!
 
Reports are accepted through and including September 15th.
 
🎟 Exclusive Promo Code
8DNLG0SN3B
 
50% discount on tickets - limited to 50 users. First come, first served.
4🔥3😈3🤩2
📋 New on Tumar.One: Report Limits
 
We are rolling out report submission limits across the platform.
 
Your limit is individual - it depends on the quality of your past reports. The default is 5 active reports at a time. Submit consistently good work and we'll raise it. Submit noise and it goes down.
 
Once a report moves out of New status, a slot opens up and you can submit again.

Hunt smart!
🤣95😴2🫡2👍1
Limited time only! 🔥

Kcell Doubles Bug Bounty Rewards for Critical Vulnerabilities: Up to 1,000,000 KZT

September is National Cybersecurity Month in Kazakhstan, and Kcell is marking it in the way researchers appreciate most.

From September 1 to 30, the maximum reward for an eligible critical vulnerability on the Tumar.One platform doubles to 1,000,000 KZT. The scope stays wide open: all Kcell and activ domains and subdomains.

Reports must be submitted by September 30. Payouts follow the program terms: the reward applies to a confirmed vulnerability that meets the program conditions, and the final amount is set on triage.

Start hunting!
🤩10🔥52😍1🗿1
August was a reminder that old security habits die hard.
 
SQL injections in REST APIs and CMS cores, unverified digital signatures handing over full account takeovers, and .git repositories left wide open in web roots. Nearly 85% of critical findings this month boiled down to two simple mistakes: trusting client-supplied input and leaving exposed metadata in the web root.
 
Full breakdown - in the cards above. 👆
 
Stay ahead with tumar.one 😃
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
5👍3😁3🔥1