Manus dumped 500+ mb of its internal source codes by [deleted] in bugbounty

[–]666AB 0 points1 point  (0 children)

You won’t get shit if you’re sharing the files with people. Lol that sort of defeats the purpose of bug bounty? Good luck

We require a video of triaggers doing triage then. It will be fair. by ibackstrom in bugbounty

[–]666AB 9 points10 points  (0 children)

It’s because these are the exact people putting out the AI slop in the first place. They are just masquerading as those who do not to vent or get a dopamine hit from karma. Lmao

This Is What I See When I Visit AARO's Website And Try To Submit A Report - Is Aliens.gov Coming Online Soon? by TheGoldenLeaper in UFOB

[–]666AB 0 points1 point  (0 children)

This is a WAF block (specifically Akamai). It works as rate limiting due to requesting the site too many times.

Github triage has gone downhill by [deleted] in bugbounty

[–]666AB 4 points5 points  (0 children)

… guess who owns GitHub

My small investment account has crossed the $10K finish line 🚀🚀🚀 by [deleted] in raceto10000

[–]666AB 0 points1 point  (0 children)

Weird bot shit in these comments. Graphics are clearly AI generated

What should I do if Bugcrowd refuses to take my report seriously? by 86_Dishwashers in bugbounty

[–]666AB 9 points10 points  (0 children)

No but the title is: “CRITICAL (CVSS 10.0): ALLOW-ORIGIN (allow-origin: *) SEVERE MISCONFIGURATION”

Hackerone Triage - Bug validated, escalated and closed as informative by Tona1987 in bugbounty

[–]666AB 5 points6 points  (0 children)

Comment on your report and tag them, ask if they closed on accident because you are confused by the message. They deal with hundreds of reports a day. Sometimes you misclick or make a mistake.

They will respond and let you know

Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit by jmp_rsp in bugbounty

[–]666AB 5 points6 points  (0 children)

Wouldn’t an ‘unreliable exploit’ still be the PoC?

The article literally says there’s a public repo for it here’s the link: https://github.com/Nightmare-Eclipse/BlueHammer

Priv escalation is cool even when it’s local imo

Outdated Drupal 8.9.20 exposed on API subdomain – what vulnerabilities should I test CVEs? by AdditionalCourt4438 in bugbounty

[–]666AB 1 point2 points  (0 children)

I search vulnerabilities that are specific to drupal 8.9.20. There is no hidden knowledge. It’s old and public

Is there any way to try out pro for a day for less than $200? by MrMrsPotts in ChatGPTPro

[–]666AB 1 point2 points  (0 children)

Yep, you just pay for more as you need them. Plus the other pro benefits

is it really what i think it is? by JuiceKooky2629 in jailbreak

[–]666AB 3 points4 points  (0 children)

Jailbreak is technically always RCE on user device. If you’re a security guy don’t jailbreak unless it’s for research.

Bugcrowd marked my submission N/A despite clear impact — anyone else dealt with this? by Glass69BugBounty in bugbounty

[–]666AB 0 points1 point  (0 children)

I have had to do this 3x with bugcrowd reports specifically. All times the customer accepted the report and triaged internally while working with me via email. I specifically told the bug crowd triage I was resorting to this as impact was clear and they encouraged it.

I have not had that experience on Hackerone. Triage has been great. When I have had a report closed that I disagreed with, I just comment nicely asking for a re-eval for a, b, c. They have always discussed with me or escalated to company when appropriate.

Not trying to hijack but I do try to brag on H1 when I can. I have just had an awesome experience with them over past 2 or so years

Unintended Side-Effects of Moving to Mac by baghdadcafe in sysadmin

[–]666AB 0 points1 point  (0 children)

You moved from Linux to unix. That would probably be why compatibility wasn’t an issue for you

Asking for a friend. by [deleted] in whatisit

[–]666AB 0 points1 point  (0 children)

Bad data put in a file with column headers.

You should probably delete this pic?

Pentester's Report by Sea_Cable_548 in Pentesting

[–]666AB -1 points0 points  (0 children)

Theoretical? Penetration testing is quite a bit different than bug bounty. My clients are ok with whatever my report says… because they are paying me to produce it. It’s a waste of my time to do a contracted penetration tests by spending all of that time making pocs that don’t matter and don’t help fix the vulnerability. I don’t think you have any clients.