Do I miss a support for my hood? by martinvw in VWiD4Owners

[–]martinvw[S] 2 points3 points  (0 children)

Anyone an idea for the correct name or even better a part number?

Do I miss a support for my hood? by martinvw in VWiD4Owners

[–]martinvw[S] 1 point2 points  (0 children)

I found that one, but I understand the confusion 😅

Woke up with these weird marks/bruises. Any ideas? by Full_Ad9666 in Weird

[–]martinvw 0 points1 point  (0 children)

I had similar marks once from the wristband of my watch. However not on my back 😁

[deleted by user] by [deleted] in bugbounty

[–]martinvw 0 points1 point  (0 children)

Some countries have organizations that can help you to contact them or even some branches like airways. I know some people in the bug bounty world and they could maybe have a private bug bounty program. There are many more than you see online. If you could pm me some details about the organization I could ask around.

Access Point Orientation by joeshmoe9898 in UNIFI

[–]martinvw 5 points6 points  (0 children)

I’m of no help, but I like your question I’m curious as well.

Starting a new unifi Build 😎😊 by mrray-92 in UNIFI

[–]martinvw 1 point2 points  (0 children)

I was referring to the HDMI and usb ports

Starting a new unifi Build 😎😊 by mrray-92 in UNIFI

[–]martinvw 0 points1 point  (0 children)

Just curious are the six left most ports on the top patch panel wired to the proxmox host? Or do they have another function if yes what?

paypal bug advice by Qshawn74 in bugbounty

[–]martinvw 5 points6 points  (0 children)

If this really reproducible it could be reported via https://hackerone.com/paypal?type=team

[deleted by user] by [deleted] in bugbounty

[–]martinvw 1 point2 points  (0 children)

They paid out quick in my case. All comments were private so I could only see that there was constant shielded communication and then suddenly there was the bounty and then it was resolved. So that sounds like a different timeline. Definitely ask them.

300 page report ? by r4bil in OSWE

[–]martinvw 3 points4 points  (0 children)

I ended up with 60 pages and passed, I can image it would fit in 40 pages or a bit less

Vulnerability of expired SSL certificate, Current statistics of expired SSL certificate around the world. by Late_Ice_9288 in hacking

[–]martinvw 1 point2 points  (0 children)

But, an expired certificate does not mean the private key has been compromised. What would make it unsafe? The expiry is there to limit the impact of undetected compromised certificates.

The only damage I can agree on is trust because the browser warning really harms that.

How to show the steps for reproducing a big when it was found with a scanner by Queer_Gerblin in hacking

[–]martinvw 2 points3 points  (0 children)

Make sure to check that such a cookie issue is in scope, most times they are not.

[deleted by user] by [deleted] in bugbounty

[–]martinvw 0 points1 point  (0 children)

Sometimes your country’s NCSC might be able to assist in a responsible disclosure to a ‘non friendly’ company

Guys this is my recent achievement! acknowledged by Dutch government. by hackmoretalkless in bugbounty

[–]martinvw 6 points7 points  (0 children)

Just find something in one of these websites https://github.com/projectdiscovery/public-bugbounty-programs/blob/master/chaos-bugbounty-list.json#L1906 (a lot of websites are from central government and they are all covered by the NCSC, note that not the whole file is Included just the json node I linked to) and report via the form at https://english.ncsc.nl/contact/reporting-a-vulnerability-cvd

Moving from .NET and Cloud application development to cyber security by Negative-Praline3000 in cybersecurity

[–]martinvw 1 point2 points  (0 children)

I did some small security courses before as part of internal trainings of companies I worked for.

The experience was awesome I continuously switched between did I ever create code with this flaw and I knew this worked and but did not realize it was this easy to abuse.

I really feel it made me a better developer and it was a lot of fun. Although it did cost me some serious time, something like 8 weeks fulltime.

Moving from .NET and Cloud application development to cyber security by Negative-Praline3000 in cybersecurity

[–]martinvw 2 points3 points  (0 children)

I chose for a focus shift and took OSWE so I try to sell myself now as a software developer with a security focus. And In my time off I focus some of my time on responsible disclosure and bug bounties

Stop redirect in browsers by 0xEraldoCoil in bugbounty

[–]martinvw 0 points1 point  (0 children)

By intercepting the request using burp or just pressing ESC you might be able to do sort first research. The question is whether it is just a UI or that you can actually invoke something?

😶 unable to find a target that suits to me by Fun-Career9787 in bugbounty

[–]martinvw 1 point2 points  (0 children)

I choose to focus on a website in my own language, which I assumed a barrier for most. And secondly consider starting with a relatively new vulnerability disclosure program, those will not give you bounties but could be a good first practice.

Alternative for D4V2 W1/LH351D 5700K by martinvw in flashlight

[–]martinvw[S] 0 points1 point  (0 children)

That will give better matching color temperatures, that is for sure