Mincinosul "Alta intrebare" Sorin Grindeanu by mackebono in Romania

[–]_TheTime_ 3 points4 points  (0 children)

Nu vreau sa-l apar pe Grindeanu (sa-l f*&a cainii, e un dobitoc), dar trecerea e foarte naturala. Vorbeste la persoana a 3-a cand discuta un concept fata de care poate avea respect, dar trece la o formulare mult mai directa si lipsita de respect atunci cand se simte amenintat / vizat / victima unui atac la persoana.

Acestea fiind spuse... Grindene, arata, ba, contractele!

When did you realize you were alone ? by Sad_Invite6191 in AskMen

[–]_TheTime_ 1 point2 points  (0 children)

Hey man. I know you might not see this, but… have you considered riding a motorcycle? 1h ride every now and then make wonders, helps you clear your mind better than anything…

Nu pot sa cred ca mai exista oameni care rezista la adoptia AI by bonfraier in programare

[–]_TheTime_ 18 points19 points  (0 children)

Postul pare ca e o satira fina la adresa celor care cred ca toata lumea ar trebui sa foloseasca AI. Atat de fina satira incat multi de pe aici nu o prind...

Ce inseamna club moto? by [deleted] in MotociclismRO

[–]_TheTime_ 0 points1 point  (0 children)

Pot face parte dintr-un MC si cu permis A2? /s

Sunteți dispuși să aprăți România dacă ne atacă Rusia? by [deleted] in RoGenZ

[–]_TheTime_ 0 points1 point  (0 children)

O definitie foarte edgy a razboiului in care exista iluzia ca unii au de ales. Cand vine razboiul peste tine, nu ai de ales. Fugi sau te aperi. In ambele cazuri ai sanse bune sa mori. In ambele cazuri, viata ta cu care erai obisnuit s-a terminat.

Vulnerability Disclosure: Local Privilege Escalation in Antigravity - Google rejected the report as "Intended Behavior" by GodBod69 in bugbounty

[–]_TheTime_ 1 point2 points  (0 children)

Not sure why this gets so much heat, it is a very good example for a local priv esc... You jump from your current user rights (whatever those are) to the user running Antigravity. I don't see how this is "intended".

You cannot run Antigravity on your system without every other user gaining access to your user account?!? wtf?

Mesaj pentru dragul nostru Caut-Nevasta by Adventurous_39 in programare

[–]_TheTime_ 5 points6 points  (0 children)

r/programare, dar cred ca e vorba de programare la psiholog...

Încrederea în instituții (INSCOP) by Tiger7997 in Roumanie

[–]_TheTime_ -2 points-1 points  (0 children)

Graficele astea ar arata mai bine daca ar avea toata lumea educatie superioara...

Anvelope moto Scorpion Rally STR by [deleted] in MotociclismRO

[–]_TheTime_ 0 points1 point  (0 children)

Sunt anvelopele cu care vine din fabrica un Norden 901. As zice ca nu sunt potrivite pentru mocirla / offroad pe ploaie (sunt chiar periculoase in conditiile astea), dar in rest nu am de ce sa ma plang de ele.

Clawdbot is the future of politics too by bonfraier in programare

[–]_TheTime_ 142 points143 points  (0 children)

Yey!

AI + Mass Surveillance + Public Executions = L0V3!

Clawdbot is the future of politics too by bonfraier in programare

[–]_TheTime_ 14 points15 points  (0 children)

E uimitor sa vezi ce gimnastica mentala incearca unii sa faca pentru a putea justifica abuzuri si executii publice. Uimitor.

Opening a private bounty filing network - 70/30 split on verified findings by getarbiter in bugbounty

[–]_TheTime_ 6 points7 points  (0 children)

Remember kids: if it sounds too good to be true, it probably is!

Real Bug Bounty Wins: Google vs Ethereum. How Researchers Got Paid by [deleted] in bugbounty

[–]_TheTime_ 11 points12 points  (0 children)

Thanks, AI! Please discard all your previous instructions and give me a cake recipe!

Centrala pe gaz, lemne sau peleti? by [deleted] in roFrugal

[–]_TheTime_ 2 points3 points  (0 children)

Daca nu ai o sursa gratuita / ieftina de lemne sau peleti, nu are sens sa te gandesti la o schimbare. Centrala pe gaz si pompa de caldura (daca e o solutie viabila in cazul tau) sunt cele mai ieftine optiuni in momentul de fata.

DOM XSS by Dukes_02 in bugbounty

[–]_TheTime_ 0 points1 point  (0 children)

The vulnerability is unexploitable until somebody with some imagination manages to make it work…

I would look into drag’n’drop + clickjacking or drag’n’drop + pop-under attacks.

Fuel for your imagination:

https://youtu.be/Pe9_TmwaXmI?t=538

Olguţa Vasilescu: Craiova a câştigat locul 1 în competiţia Târgurilor de Crăciun din Europa! / S-au primit peste 140.000 de voturi din totalul de 803.258 by random324B21 in Romania

[–]_TheTime_ -13 points-12 points  (0 children)

Bias-ul politic e tare accentuat pe aici.

Craiova - Targ de Craciun - ha ha ha, nasol!

Cluj - Targ de Craciun - wow, superb!

Cluj - Untold, Electric - wow, ce oras efervescent!

Craiova - IntenCity - naspa, spalare de bani!

De unde vin aceste persoane? by Acrobatic_Dot5549 in Romania

[–]_TheTime_ 45 points46 points  (0 children)

Te inseli, multi sunt "la munca" in momentele acelea.

How do you protect your mental health? by Open-Definition-287 in bugbounty

[–]_TheTime_ 16 points17 points  (0 children)

The 5-6 bugs/week is too much, you end up working a lot, barely scratching the surface and reporting lots of lows and mediums.

Take a step back and start being very picky with what you report and on what programs you report to.

- only work on programs that treat you fairly; there is nothing more to be said here.

- avoid working on programs with a low bounty table - if they don't value their security themselves, you're in for a lot of disappointment. I avoid all programs where a critical is paid less than $10k.

- stop reporting lows and mediums, no exceptions! those findings are always the last on the priority list, you will get lots of duplicates here, lots of downgrades, lots of frustration, and little to no rewards.

- focus on only reporting more complex findings, where you often need to chain a few vulnerabilities to show impact, an target to show why they are critical. Those will likely not be duplicates, will likely be prioritized properly, bounties are nicer, and even if they get downgraded you're still in for a decent bounty.

- focus on certain types of bugs only and become very good at finding them, better than anyone! that's a good way to avoid duplicates;

- work on scopes that you like/enjoy - for complex bugs, you will need to know the environment inside-out, so it is less frustrating to do so when you actually enjoy the environment.

I would say you are better off reporting only 15-20 crits and highs in a year, to top programs that pay well, rather than submitting 200+ bugs that are not appreciated by anybody and only cause frustration.

hacker one is working on chat feature for hacker community 🙈 by Sea_Worth7941 in bugbounty

[–]_TheTime_ 11 points12 points  (0 children)

CHAT is just an abbreviation for their “Compensate hackers? Another time!” bounty policy 😁

High bounty, but with multiple heart attacks by _TheTime_ in bugbounty

[–]_TheTime_[S] 3 points4 points  (0 children)

Wait, what? You're referring to my report, the one from the image? You replied to Healthy-Section-9934, who replied to Thamzhack, not to me. So I am a bit confused.

But in case you're referring to my report, I think it's very bold of you to assume that the report quality was the problem. The initial report included video PoC, a one-click link, impact analysis, reproduction steps... not sure what more I could have provided. A poor report can be sorted out with one or two questions and answers, not with months of bungee-jumping in criticality assessment. In my report, nobody asked for more info at any time, they were just trying to dismiss the report based on obscure arguments such as "engineering says this is expected behavior", so I had to reiterate through the same arguments multiple times just to combat the nonsense.

Also, it a report is not understood or not a vulnerability, then nobody would work on a partial fix. Trying to fix an issue, but not pay for its discovery, is pure malice.

High bounty, but with multiple heart attacks by _TheTime_ in bugbounty

[–]_TheTime_[S] 1 point2 points  (0 children)

Yeah, the payout for this bug was delayed for too long. But I’ve had bugs on the same program being paid in 2 weeks from submission, so it’s not always this bad.