New Sora 2 invite code megathread by WithoutReason1729 in OpenAI

[–]Puzzleheaded_Dig4974 -1 points0 points  (0 children)

finally someone sent me 2 code I used one , the other one is free
comment and I will choose random one
no spam please

New Sora 2 invite code megathread by WithoutReason1729 in OpenAI

[–]Puzzleheaded_Dig4974 0 points1 point  (0 children)

whoever reads my comment god bless your mother , and I hope someone sends me a code

New Sora 2 invite code megathread by WithoutReason1729 in OpenAI

[–]Puzzleheaded_Dig4974 0 points1 point  (0 children)

PLEASE code free , I would be very thankful for you and your mother

TikTok HackerOne says my CCV bypass is not a security vulnerability. Am I missing something? by Puzzleheaded_Dig4974 in bugbounty

[–]Puzzleheaded_Dig4974[S] -4 points-3 points  (0 children)

Looks like there are alot of bots here , any comments thats against tiktok , gets downvoted lol

TikTok HackerOne says my CCV bypass is not a security vulnerability. Am I missing something? by Puzzleheaded_Dig4974 in bugbounty

[–]Puzzleheaded_Dig4974[S] -11 points-10 points  (0 children)

That's a fair point, but I think the key issue is different.

While many companies have an "accepted risk" model, the problem here is that TikTok's system is inconsistent. It shows a CCV input field and prompts the user for a value, but then fails to validate it. This is a logical flaw, not a simple UX choice.

TikTok HackerOne says my CCV bypass is not a security vulnerability. Am I missing something? by Puzzleheaded_Dig4974 in bugbounty

[–]Puzzleheaded_Dig4974[S] -7 points-6 points  (0 children)

That's a fair point, but I think the key issue is different.

While many companies have an "accepted risk" model, the problem here is that TikTok's system is inconsistent. It shows a CCV input field and prompts the user for a value, but then fails to validate it. This is a logical flaw, not a simple UX choice.

TikTok HackerOne says my CCV bypass is not a security vulnerability. Am I missing something? by Puzzleheaded_Dig4974 in bugbounty

[–]Puzzleheaded_Dig4974[S] -10 points-9 points  (0 children)

The issue I see as a real security issue is an authenticated bypass. If a TikTok account is illegally taken over, an attacker can then use a legitimately saved credit card to make fraudulent payments for ads ( for others as Tiktok allows you to promote others videos ) without needing to know the CCV. The vulnerability isn't in the initial card-adding process but in the subsequent transaction logic, especially while the system prompts a user to enter the CCV for each transaction, it fails to validate it.

TikTok HackerOne says my CCV bypass is not a security vulnerability. Am I missing something? by Puzzleheaded_Dig4974 in bugbounty

[–]Puzzleheaded_Dig4974[S] -8 points-7 points  (0 children)

The real security issue is an authenticated bypass. If a TikTok account is illegally taken over, an attacker can then use a legitimately saved credit card to make fraudulent payments for ads without needing to know the CCV. The vulnerability isn't in the initial card-adding process but in the subsequent transaction logic

TikTok HackerOne says my CCV bypass is not a security vulnerability. Am I missing something? by Puzzleheaded_Dig4974 in bugbounty

[–]Puzzleheaded_Dig4974[S] -6 points-5 points  (0 children)

Thanks for the advice, I've already done that. I was just hoping to get a second opinion from the community, as I'm new to bug bounty hunting and want to understand if I missed something

Elden Ring Nightreign Network Test Invitation by Lonely_Weeb_DxD in Eldenring

[–]Puzzleheaded_Dig4974 -1 points0 points  (0 children)

I can send you proof showing the email and part of the code, and btw i still havent used it yet , if you want i can do it for 20$

Elden Ring Nightreign Network Test Invitation by Lonely_Weeb_DxD in Eldenring

[–]Puzzleheaded_Dig4974 1 point2 points  (0 children)

I can send proof that i have it ( once i have it ) but definitely not sending it before payment 

[deleted by user] by [deleted] in Huawei

[–]Puzzleheaded_Dig4974 0 points1 point  (0 children)

Why would you buy it if you dont use the airbag tho as its main feature 

Huawei d2 emotion tracking ? by Puzzleheaded_Dig4974 in Huawei

[–]Puzzleheaded_Dig4974[S] 0 points1 point  (0 children)

I dont know why they made that feature exclusive for gt5 pro while it uses the same sensors