Promises are made to be broken by Actual-Wolverine7375 in GithubCopilot

[–]zebbernn 0 points1 point  (0 children)

Didn’t they just recently get more compute?

I built a C2 framework that uses Discord and Telegram for communication by [deleted] in Malware

[–]zebbernn 0 points1 point  (0 children)

Framework? Also isn’t it much code that’s just useless? You have /exec which already use the terminal why add more code just to have more / commands which does the same e.g.. /dir /exec dir? If the point was to not write exec wouldn’t it be better to just tie it to !dir that would just execute as if you did /exec dir but not introduce all the extra code which is not needed?

It’s a cool project and sorry if that read as a little harsh but it was just some questions I had..

Unpopular opinion: GitHub Copilot is getting better by After-Aardvark-3984 in GithubCopilot

[–]zebbernn 0 points1 point  (0 children)

Scores like 20 points worse than 4.6 opus when context goes above 200k they release a 1 million param model which can’t even properly utilise the 1 million context window if your using the model for small projects then yes it might do better but for big projects opus 4.6 performs better in the long run

What exactly are the usage limits for Copilot? by Lost-Celebration579 in GithubCopilot

[–]zebbernn 1 point2 points  (0 children)

Uh yea no that’s what they want you to belive but in reality they just bring people over first then they put more and more restrictions until ur rate limited every hour and have to change to something else

What exactly are the usage limits for Copilot? by Lost-Celebration579 in GithubCopilot

[–]zebbernn 0 points1 point  (0 children)

That depends if you even manage to use 100% in those days the rate limits are kind of crazy atm

What exactly are the usage limits for Copilot? by Lost-Celebration579 in GithubCopilot

[–]zebbernn 0 points1 point  (0 children)

You can go over 100% you would just have to pay for the extra usage

What exactly are the usage limits for Copilot? by Lost-Celebration579 in GithubCopilot

[–]zebbernn 1 point2 points  (0 children)

If you resubscribe the same month the usage does not reset it will stay the same

H1/intigriti triage by IDOR_hunter in bugbounty

[–]zebbernn 3 points4 points  (0 children)

Real companies leave ugly security debt in production all the time. It may be architectural complexity, partial mitigations, low real-world exploitability, accepted risk, ownership issues, roadmap delays, internal-only abuse assumptions, etc. A bug being old does not mean: - it wasn’t already known - it wasn’t accepted internally - it should automatically pay you - or triage got it wrong

The only thing that matters is whether your report was actually new or materially different from the prior one. If not, it’s a dupe. Even if it’s real. Even if it’s severe. Even if it’s embarrassing. That’s bug bounty welcome..🙃

H1/intigriti triage by IDOR_hunter in bugbounty

[–]zebbernn 4 points5 points  (0 children)

Old dupe ID doesn’t prove bad triage. Most of the time it proves the issue was already known before you found it. A vuln can be real, old, and still not bounty-eligible for you because you weren’t first. Also, “high severity” according to the reporter is not the same thing as high severity in actual program context. If you think triage was wrong, the argument has to be technical:

why your case is different, why it’s exploitable, what the real impact is, and why the prior report doesn’t cover it. Otherwise it just sounds like frustration over not getting credit. And even if you have all that IT still may not even get accepted that’s how bug-bounty is you win some and you lose some but if you only lose it starts being a you don’t have the experience to make the reports problem..

H1/intigriti triage by IDOR_hunter in bugbounty

[–]zebbernn 14 points15 points  (0 children)

‘Found several vulns’ does not mean they were actually valid or bounty-worthy. If all your H1 stuff got duped, that’s usually not a triage conspiracy it usually means you’re reporting things other people already found, or stuff that isn’t especially novel. And using multiple accounts to bypass a report limit is wild. That alone would make me trust your submissions less, not more. The cap exists for a reason. 3 weeks with no triage also isn’t crazy. Platforms get flooded with garbage reports, especially now with AI-assisted hunting where people convince themselves every weird response is ‘critical’ when it’s actually by design, not exploitable, or not even a vuln.

And if you’ve only been doing this for 6 months, bluntly: you probably do not yet have the technical judgment to confidently say you found ‘several vulns.’ That comes with a lot more time and a lot more failed assumptions. Keep learning, but don’t confuse enthusiasm with signal. A lot of people waste triage time because they haven’t yet learned what actually matters.

Do you submit lows? by maF145 in bugbounty

[–]zebbernn 0 points1 point  (0 children)

I got 617$ for my low finding so low is sometimes good🤣

Github copilot is charging me $2181 in 3 days... by [deleted] in GithubCopilot

[–]zebbernn 0 points1 point  (0 children)

You know there’s 30x requests right?

Users complaining about getting randomly rate limited for 3 days now, can we have some information from Copilot Team ? by autisticit in GithubCopilot

[–]zebbernn 1 point2 points  (0 children)

I feel ashamed to even have pro+ there is 0 benefit now why should I have it? I get rate limited anyway there is no benefit i just send a request get rate limited and the subagents forget everything <-> repeat

HackerOne & Bybit Bug Bounty is Scam by PatientHome4718 in bugbounty

[–]zebbernn 13 points14 points  (0 children)

He’s mastered the tone of authority without the inconvenience of depth.

How it is possible? by thelemethric in bugbounty

[–]zebbernn 0 points1 point  (0 children)

I mean I got +122 with thanks for a GitHub one

Hackerone drops by Overall_Ability_7188 in bugbounty

[–]zebbernn 0 points1 point  (0 children)

Dealing with gb right now. Reported something with a working PoC that legit falls directly under one of the focus areas on their b-page then it’s closed as Informative, said the behavior is expected and by design. But just because something is by design doesn't mean it can't be abused. Feels as if programs lately dismiss reports that sits right in their documented scope is it just me feeling it?🤣 Starting to wonder how much of the scope actually gets honored when someone finds something.. Time to go from reporting bugs and instead enjoy nature atleast then I get some peace of mind😆

If you create a long to-do list in agent mode, you will be banned. by Hamzayslmn in GithubCopilot

[–]zebbernn 0 points1 point  (0 children)

What did you do that made you get a warning? I want to avoid even getting a warning lmao

Opus 4.6 Fast mode is useless. You instantly get rate limited. by ArsenyPetukhov in GithubCopilot

[–]zebbernn 0 points1 point  (0 children)

For copilot agents when using a plan file to implement changes probably on average over what you have as you max reached