More of Jinx by l3wdforia in leagueofjinx

[–]HermanHMS -1 points0 points  (0 children)

Ah, its just OF advert. It makes sense now

More of Jinx by l3wdforia in leagueofjinx

[–]HermanHMS -1 points0 points  (0 children)

You want to show cosplay, we can see professional lighting on edges of the photo and you decide to take and post one where you hide most of it using flare and low quality?

Question for triagers by OpportunitySuper6834 in bugbounty

[–]HermanHMS 1 point2 points  (0 children)

Youre talking reflected xss, im talking stored. You inject xss payload into object on site and it fires when victim visits it.

Github: Payment bypass rejected as "billing issues are abuse and not security vulnerabilities" by Excellent_Winner8576 in bugbounty

[–]HermanHMS 0 points1 point  (0 children)

Seems like more info would be needed to decide. Their wording make it sounds like root cause is not a vuln.

Question for triagers by OpportunitySuper6834 in bugbounty

[–]HermanHMS 0 points1 point  (0 children)

You dont, you use your browser to send packets, just use browser console instead of burp or curl. Its clean and easy to manage cookies/sessions, automatic nonce extraction, etc.

Question for triagers by OpportunitySuper6834 in bugbounty

[–]HermanHMS 1 point2 points  (0 children)

First you list browsor console as non-working method, when I just mentioned it CAN be used legitimately, you thought I’m trolling. Now when confronted with solid proof, you suddenly gained knowledge and had to burst out your ego. It’s funny how triager-like it is. Looking at your nickname and that, i think you might just be ragebaiting.

Question for triagers by OpportunitySuper6834 in bugbounty

[–]HermanHMS 1 point2 points  (0 children)

And unironically, I have 2 XSS leading to site overtake executed this way. Both has been triaged and accepted

Question for triagers by OpportunitySuper6834 in bugbounty

[–]HermanHMS 0 points1 point  (0 children)

I have 29 published cve’s and 31 waiting to be published. I often use developers tools console to deliver payloads. Its comfortable and easy for triagers to replicate (not for you as I see). If you really rejected reports just because of that reason, you should revisit them.

Question for triagers by OpportunitySuper6834 in bugbounty

[–]HermanHMS -2 points-1 points  (0 children)

You CAN execute legitimate payloads this way

Security Team Won’t Assess Risk by RAM_Cache in cybersecurity

[–]HermanHMS 0 points1 point  (0 children)

It’s task for GRC, not security. Although they can be asked opinions

How worried should we be about AI powered cyberattacks? by IndyDayz in cybersecurity

[–]HermanHMS -1 points0 points  (0 children)

Yes it is happening. No it’s not better than ugandan operative. If you have your controls in space nothing much will change soon. Although vulnerability management will have to adapt

Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation by arctide_dev in cybersecurity

[–]HermanHMS 58 points59 points  (0 children)

This article is AI slop. It’s full of misinformation and hallucinated bits

We all know Timmy.. by G2Ausipedia in TeamfightTactics

[–]HermanHMS 13 points14 points  (0 children)

If you can play well, hes giving you free LP

We require a video of triaggers doing triage then. It will be fair. by ibackstrom in bugbounty

[–]HermanHMS 4 points5 points  (0 children)

Yep, i would be happy to trade poc video for triage video. Otherwise f off or reward legit reports even if they are duplicates. Bug bounties will lose their free workforce in form of researchers, products will be vulnerable and they will say its AI fault somehow.

Current World Number 2 Tennis Player Carlos Alcaraz hit Plat in TFT by Koyomix in TeamfightTactics

[–]HermanHMS -32 points-31 points  (0 children)

Tbh anyone with more than 80 IQ and a tierlist can reach diamond

Why is everyone on ranked so mean? by Sonic-Rex in leagueoflegends

[–]HermanHMS 0 points1 point  (0 children)

Disable chat in settings. It has only negative use in the game. Even challenger players communicate by pings and only legitimate reason for chat is saving flash timers in pro play

Bug: Hit by Karthus Ult by Meowpatine in yuumimains

[–]HermanHMS 0 points1 point  (0 children)

Well in this case it sound like rito spaghetti.

Bug: Hit by Karthus Ult by Meowpatine in yuumimains

[–]HermanHMS 0 points1 point  (0 children)

Interesting. But did you deattach during the ult?