0xHun73r

199 posts

0xHun73r banner
0xHun73r

0xHun73r

@0xHun73r

Security Researcher.

/endpoint Katılım Ocak 2025
216 Takip Edilen532 Takipçiler
0xHun73r
0xHun73r@0xHun73r·
@SlowBearDigger Indeed and i think if things keep going this way the black market will likely rise again i mean no one wants to waste their time only to get scammed in the end by these companies
English
1
0
1
32
SlowBearDigger
SlowBearDigger@SlowBearDigger·
Yeah, but to be honest? i think is just a dirty policy/marketing move... "Look we are secured by XXXXX program!" "Look! 0 payouts we safe!" and in the reality, they ignore the whitehats, close valid reports as informative to not pay, and keep it like that... i send a ticket to support and it says: "Per XXXXXXX's own bug bounty process documentation, the platform reserves the right to review reports when researchers notify of a reduced reward or severity, and will delist companies that attempt to reduce hacker rewards inappropriately. XXXXXXX's own triage team confirmed this report as valid (High). XXXXXXXXXX overturned that decision citing a technical argument that is factually incorrect per Sui's execution model. This is precisely the scenario your policy covers. I am formally requesting XXXXXXXX to exercise its review authority on this case." we shall see but that practice should be banned always and everywhere, they're making us lose time and patience
English
1
0
2
44
0xHun73r
0xHun73r@0xHun73r·
idk why they changed the severity to low when this is clearly high. i contacted them asking to reconsider the severity (hope they do) but seems like they're gonna take way too long to reply so I'm just gonna drop the writeup tomorrow Inshallah and hope u like it
0xHun73r tweet media
English
1
1
56
2.1K
0xHun73r
0xHun73r@0xHun73r·
@SlowBearDigger Actually there are some companies that don't consider such issues as vulnerabilities i mean they don't see it a problem if the user did somth like that which is clearly wrong
English
1
0
1
36
SlowBearDigger
SlowBearDigger@SlowBearDigger·
@0xHun73r Idk what's the matter with some teams, like 20 mins ago something like that happened to me a clear critical, Poc, all valid and within scope > informative... also waiting to see if the platform's support does anything..
English
1
0
2
160
0xHun73r
0xHun73r@0xHun73r·
@3ugman That's part of the game just keep going and don't give up bro
English
1
0
2
68
0xHun73r
0xHun73r@0xHun73r·
i found that writing a writeup is harder and more boring than I expected lol
English
0
0
6
245
0xHun73r
0xHun73r@0xHun73r·
@Younis_J_ ارسلي ال poc ممكن افيدك ان شاء الله
العربية
1
0
1
31
Younis Jabr
Younis Jabr@Younis_J_·
@0xHun73r يارب ...اتمنى يكون اول باونتي
العربية
1
0
2
132
Younis Jabr
Younis Jabr@Younis_J_·
قبل فتره كنت بلغت ثغرة IDOR كانو طلبو دليل وكذا لاني الثغره ما تأثر في مستخدمين بشكل مباشر لا بس في integration تبع الشركه اعطيتهم إثباتين مع فيديو كان هذا ردهم الأخير وأتمنى جداً تنقبل لاني هذا اقرب حاجة وصلت له ولا الباقي كلو عباره عن DUP وINFO #Cybersecurity
Younis Jabr tweet media
العربية
3
0
41
2.6K
0xHun73r
0xHun73r@0xHun73r·
@ironCardSec Indeed thanks man. I'll drop a writeup about it in the coming days inshallah
English
0
0
2
78
0xHun73r
0xHun73r@0xHun73r·
Yoo If this report gets triaged, I'm back to daily bug bounty hunting. Let’s pray for this one guys lol
0xHun73r tweet media
English
2
1
86
2.8K
0xHun73r
0xHun73r@0xHun73r·
@adce626 الله يبارك فيك
العربية
0
0
2
26
0xHun73r
0xHun73r@0xHun73r·
And btw, my friend 0xAlchemist and I managed to get alhamdulillah 4 CVEs in an open source CMS plugin while I was vanished.
English
1
0
11
816