Dat Pham 🇻🇳

169 posts

Dat Pham 🇻🇳 banner
Dat Pham 🇻🇳

Dat Pham 🇻🇳

@datph4m

Bughunter

localhost Katılım Kasım 2019
411 Takip Edilen1.5K Takipçiler
Dat Pham 🇻🇳 retweetledi
James Kettle
James Kettle@albinowax·
You can now scan for #react2shell in @Burp_Suite. To enable, install the Extensibility Helper bapp, go to the bambda tab and search for react2shell. Shout-out to @assetnote for sharing a reliable detection technique!
James Kettle tweet media
English
7
106
640
43.4K
Dat Pham 🇻🇳 retweetledi
Flysec Corp
Flysec Corp@flysec_corp·
Congrats🇻🇳squad's good win with 2nd highest score in the 1/8 finals of the #AmbassadorWorldCup, secure a spot in the Elite Eight round at Prague, 🇨🇿! 🔥Flysec has a great hacking experience in AWC 1/8 finals being in Top 1 of Report Leaderboard! Fighting for semi-final spot!
Flysec Corp tweet mediaFlysec Corp tweet mediaFlysec Corp tweet mediaFlysec Corp tweet media
English
3
3
60
5.3K
Sarmad Hassan
Sarmad Hassan@JubaBaghdad·
@datph4m curios why the bounty was low, is there any limitation?, like unpredictable video IDs?
English
2
0
1
200
Dat Pham 🇻🇳
Dat Pham 🇻🇳@datph4m·
TikTok has a private program where they mention that: "Private posts and .... is usually high-critical." Yes, initially, I reported this issue through that program. After they reviewed it, they transferred my report to the main program (TikTok) and downgraded it to medium.
Dat Pham 🇻🇳 tweet media
English
1
0
20
1.3K
Hugo Picanzo
Hugo Picanzo@hugopicanzo·
@datph4m @disclosedh1 Yeah I would say pretty critical. Can I ask if it was a regular numerical IDOR or more complex?
English
1
0
0
133
Dat Pham 🇻🇳
Dat Pham 🇻🇳@datph4m·
@696e746c6f6c They always tried to downgrade the severity to avoid paying a bounty large. I decided to leave the program after this report.
English
1
0
3
361
Dat Pham 🇻🇳
Dat Pham 🇻🇳@datph4m·
I discovered an endpoint that allows retrieving all videos from a private TikTok user, and he consider the confidentiality impact to be Low. #bugbounty #hackerone
Dat Pham 🇻🇳 tweet media
English
6
4
106
8.9K
Dat Pham 🇻🇳
Dat Pham 🇻🇳@datph4m·
3/ Compared to the report that earned the $8,000 reward, the private video disclosure issue was more severe. However, they managed to downgrade it to a medium severity level and fixed it within 24 hours.
Dat Pham 🇻🇳 tweet media
English
0
0
4
1.2K
Dat Pham 🇻🇳
Dat Pham 🇻🇳@datph4m·
1/ Last month, I was awarded $8,000 for identifying a user privacy-related issue.
Dat Pham 🇻🇳 tweet media
English
2
1
9
1.8K
Dat Pham 🇻🇳
Dat Pham 🇻🇳@datph4m·
2/ I can’t disclose much, but a TikTok employee has confirmed it.
Dat Pham 🇻🇳 tweet media
English
0
0
0
831
Dat Pham 🇻🇳
Dat Pham 🇻🇳@datph4m·
TikTok has a private program. If you’re part of this program, It can be seen in the program’s policy that video disclosure is considered Critical. I initially reported the issue there, but they transferred it to their public program and downgraded the severity to Medium.
English
0
1
11
1.5K