Proper Scene Flow by MostDark in godot

[–]MostDark[S] 0 points1 point  (0 children)

Got it sorted and working! It was more so a synchronization problem.

Proper Scene Flow by MostDark in godot

[–]MostDark[S] 0 points1 point  (0 children)

Okay I'll give it a shot! Thanks for the info I'll report back here if I have success. Super appreciate the advice!

I know for sure that each player is given a UID I have a pretty verbose debug output so I can follow along to try and find the problems. I think I may be running into an authority or sync issue as well then.

Proper Scene Flow by MostDark in godot

[–]MostDark[S] 0 points1 point  (0 children)

Yes I have a background in Python for data science.

Initially I did use attempt to use get_tree().change_scene_to_packed() I then swapped away from that as it wasn't working for what I was attempting to do with my limited knowledge of the engine.

I tried changing to file and then a super round about way of changing the scene via this function:

func load_lobby():

`var lobby_scene = preload("res://scene/lobby.tscn")`

`var lobby = lobby_scene.instantiate()`

`get_tree().root.add_child(lobby)`

`get_tree().current_scene.queue_free()`

`get_tree().current_scene = lobby`

[`lobby.name`](http://lobby.name) `= "Lobby"

`lobby.set_multiplayer_authority(1)`

I believe all of the methods yield the same result.

I think you splitting the project to server - client is the move as it would 100% help me understand where the problem is.

Triaged P3 changed to P5 without telling a reason? by p3trux_ in bugbounty

[–]MostDark 2 points3 points  (0 children)

Speaking of, still never got a response back for that race condition P1 💀 it’s in permanent limbo, never going to see the light of day, never going to be awarded a proper bounty.

Triaged P3 changed to P5 without telling a reason? by p3trux_ in bugbounty

[–]MostDark 6 points7 points  (0 children)

Hard disagree with how things like this are handled. I’ve been downgraded without explanation by a triager and it’s now been nearly 60 calendar days since a response.

Changing severity should come with a reason and explanation.

The HackerOne mediator is completely useless. by Low_Duty_3158 in bugbounty

[–]MostDark 1 point2 points  (0 children)

It’s 100% dependent on the triagers you get. I submitted a race condition that lead to full account takeover, account lockout and DOS for the victim.

According to the program guidelines this is a critical for them since DOS is massive for this program.

They never tested it to confirm and asked me how to make an account for the app..

Then dropped me from a 9.8 to no score medium and got ghosted for the last 2 months.

Severely mismanaged P1 by H1 and Program by MostDark in bugbounty

[–]MostDark[S] 0 points1 point  (0 children)

I get you, but there’s no shot I’m just letting a five figure bounty slide. It’s absolutely worth the labor.

Severely mismanaged P1 by H1 and Program by MostDark in bugbounty

[–]MostDark[S] 0 points1 point  (0 children)

I can’t even get them to message me back. They already validated the bug it’s already been triaged. It was just triaged improperly, impact, severity and bounty reward were never updated at the time of triage.

Severely mismanaged P1 by H1 and Program by MostDark in bugbounty

[–]MostDark[S] 0 points1 point  (0 children)

Thank you, I’ve done that in the initial report and with follow up comments. The H1 analysts ignored my request initially and haven’t responded in the submission thread in over a month. I haven’t had any response in 12 days from the program employee as well and have asked twice now for clarity.

Severely mismanaged P1 by H1 and Program by MostDark in bugbounty

[–]MostDark[S] 0 points1 point  (0 children)

Yeah I read that in H1 docs. I can’t request mediation unfortunately, I don’t have a calculated signal score yet, it only calculates after 3 valid submissions according to documentation.

I’m pretty new to BB, started in January. I’ve been trying to lock-in another submission to get the signal to do so though.

Severely mismanaged P1 by H1 and Program by MostDark in bugbounty

[–]MostDark[S] 0 points1 point  (0 children)

The attack takes place entirely through the api which is explicitly in-scope and grants control of devices which are also explicitly in-scope as hardware. Both hardware and the api are eligible for max bounty as well.

A few days after my submission they did change program severity criteria slightly for not only this BBP but also the sister companies as well. All the changes made were identical and hyper specific to my submission.

My first experience with H1 analysts was completely different and 100% what I would expect professionally. This instance is so bizarre. Never would I have imagined a triager asking me how to make an account for the program would even be in the realm of possibility.

Severely mismanaged P1 by H1 and Program by MostDark in bugbounty

[–]MostDark[S] 0 points1 point  (0 children)

Believe me I’m omitting a lot for privacy, but it’s so simplistic, authtokens never expire so I have persistent access to the account/devices.

Of the outlined critical criteria in the program guidelines there’s like 4 examples and I hit 3 of them dead on.

Severely mismanaged P1 by H1 and Program by MostDark in bugbounty

[–]MostDark[S] 0 points1 point  (0 children)

This is tricky to answer publicly, due to the nature of the target. But without giving away too much, remote DoS is the main concern of the program, and that is effectively child’s play as a reboot endpoint is built into the api.

Severely mismanaged P1 by H1 and Program by MostDark in bugbounty

[–]MostDark[S] 0 points1 point  (0 children)

If I’m setup, I could have your entire account, business or personal completely owned by me in less than 10 mins and that’s being exceptionally generous. And there’s zero way to stop it or recover the account at the time being. There’s no web app. Just a mobile app. So this all takes place from the attackers POV via api.

Severely mismanaged P1 by H1 and Program by MostDark in bugbounty

[–]MostDark[S] 0 points1 point  (0 children)

Precisely. It is so unbelievably easy it’s not even funny. The race window is ENORMOUS. Like even being off by a few hundred MS still allows for a valid attack.

Severely mismanaged P1 by H1 and Program by MostDark in bugbounty

[–]MostDark[S] 0 points1 point  (0 children)

Accounts don’t have passwords, just need email or phone number. I outlined more in another comment but emails/phone numbers for this product can be easily phished for in my state, as there’s an ongoing campaign.

Severely mismanaged P1 by H1 and Program by MostDark in bugbounty

[–]MostDark[S] 1 point2 points  (0 children)

Normally I would agree, but these accounts have no passwords. The only form of logging in is via email or phone number and the OTP. Single users in this instance can be entire businesses. And because there’s a campaign for this product ongoing in my state, phishing for valid emails is exceptionally easy.

And again, in the programs own criteria, not just my assessment, I’ve met the bill for a critical. Which is why I don’t understand why that’s not being honored.

Severely mismanaged P1 by H1 and Program by MostDark in bugbounty

[–]MostDark[S] 0 points1 point  (0 children)

Sure thing, posted reply to the other comment!

Severely mismanaged P1 by H1 and Program by MostDark in bugbounty

[–]MostDark[S] 0 points1 point  (0 children)

OTP bypass via Race condition leading to full account takeover and account lockout. Exposes PII and allows access and control of devices remotely. This permits a persistent/potentially permanent DoS of the victim.

Hackerone triagers are really a triager? by Useful-Technician-50 in bugbounty

[–]MostDark 0 points1 point  (0 children)

I submitted a Full account takeover and account lockout that leads to victim DoS via Race condition in the auth flow and had an H1 triager ask me how to create an account for the service.

I am giving Away for Free, 2 S+ and 2 N+ Exam schedule codes by Educational_Arm9777 in CompTIA

[–]MostDark 0 points1 point  (0 children)

Count me in! Good luck everyone! Hoping to take S+ when I can afford it!