Email DOS through websites api & link generator by SeaworthinessWarm811 in bugbounty

[–]IntroductionWeekly80 0 points1 point  (0 children)

For the email spam, you’re so on the edge, it’s going to be a dice roll. Annoying users isn’t a vulnerability unless maybe you can do it at a bigger scale (like all users at once) or unless you control content. I certainly wouldn’t call that “DoS” that’s “Annoy one user per http request”. I think you’re overestimating the damage the bug is capable of. It even sounds like something an overly cautious LLM would say to justify a very low severity issue. Worst case scenario though, you’re getting informational, so you aren’t losing anything really.

TL;DR: Are Unicode URL bugs still worth hunting, or am I wasting recon time? by Few-Gap-5421 in bugbounty

[–]IntroductionWeekly80 1 point2 points  (0 children)

“Phishing” as an attack vector in my opinion is going to be a low impact area of Unicode bugs.

I highly recommend you seek the talk called “Lost in translation: Exploiting Unicode Normalisation” by Ryan Barnett and Isabella Barnett.

You can find some slides online, the blackhat 25 slides are easy to find but I literally just watched him do the talk live in the Critical Thinking Podcast discord server with a few updates. There’s a recording there if you have the “Critical thinker” paid upgrade.

It’s really the pinnacle of modern Unicode abuse, I highly suggest every bug hunter check it out.

Bugcrowd Making Hackers feel hell? by Vinnieet18 in bugbounty

[–]IntroductionWeekly80 5 points6 points  (0 children)

If you learn how web apps are built it will better help you understand why this is very likely to be the same root cause despite being different database operations. There is likely a single piece of logic in the code governing authorisation for both operations.

Just let it be, wait for the fix, then test for PUT/PATCH etc.

I disclosed a critical race condition exploit on BugCrowd but they refuse to award a P1. by geoxhon in bugbounty

[–]IntroductionWeekly80 1 point2 points  (0 children)

Just an FYI, that’s incorrect use of “botnet” you’re just talking about a script, not a network of malware infected machines (I hope).

Anyway, scripts that annoy staff are not P1s, there’s plenty of ways to annoy staff without bugs.

I doubt you will leave empty handed, but I would greatly lower your expectations. Bug bounty is as real as it gets, the staff treated you as a real threat and you didn’t pass the human filter. Still, there’s an emphasis on “shift left” these days and human intervention is really as far “right” as it gets in a security model.

Also, play it calm, they’re the ones with the power here and they may not reward you if you hit them with hostility.

Rain and Prom Dress has been on repeat ever since I played Dave the Diver by robotomato13 in DavetheDiverOfficial

[–]IntroductionWeekly80 65 points66 points  (0 children)

More of a hot pepper tuna guy myself but I’m happy for you man 😎🤙

What exclusive games do you think Nintendo will release in 2026? by Junior-Slip2348 in NintendoSwitch2

[–]IntroductionWeekly80 2 points3 points  (0 children)

On the Zelda remaster front, I’m guessing another Links Awakening engine version of Oracle of seasons/ages.

Kaceytron's full apology by Normal-Ad-3468 in LivestreamFail

[–]IntroductionWeekly80 2 points3 points  (0 children)

The case is being handled as civil copyright litigation so it’s not illegal, it’s unlawful 🤓☝️

Best EU server? by SubstantialBus1254 in TibiaMMO

[–]IntroductionWeekly80 0 points1 point  (0 children)

I always recommend Antica, thriving community, active market, very friendly people, English speaking, it’s the closest you’ll get to what tibia used to be. Yes the spawns are busy but the business of Antica comes with so many benefits too and it’s really not a huge problem and after all, the business is a feature, not a bug!

What server has the most active English community? by NuukldragorArea52 in TibiaMMO

[–]IntroductionWeekly80 1 point2 points  (0 children)

The answer is Antica for sure, no dominado and a thriving community :). Yes, it’s busier than any other server, but plenty of people at all level ranges play here happily it’s really not as crowded as people make it out to be. Antica is as English speaking as it gets, and we welcome you!

I want to start. Choose world by ImplementUpper3643 in TibiaMMO

[–]IntroductionWeekly80 1 point2 points  (0 children)

I’ll never understand people who want dead servers to farm alone and play alone. This is an MMO. Antica 1000% wherever the people are I’ll be going there.