SlowBearDigger

2.5K posts

SlowBearDigger banner
SlowBearDigger

SlowBearDigger

@SlowBearDigger

Whitehat hacker at @HackenProof | Web Dev | XMR Maxi XMR: 42w9YaCW8UwZ2BmQztNmUd6JgYVcjW7LXEMTcQqHdmtFCsSo5RGY2eQg2iZ3WyBSSs63gnhczLkJ46yfr4ojCXWT3H1ZBbR

Quito, EC. Katılım Mayıs 2024
213 Takip Edilen638 Takipçiler
Sabitlenmiş Tweet
SlowBearDigger
SlowBearDigger@SlowBearDigger·
Hey yall! Papa Bear here!! gonna launch somethin huge, GOXMR!!!! ATTENTION!!! goxmr.click IS LIVE, UP AND RUNNIN!!!! Ah, yeah!! OpenSource: github.com/SlowBearDigger… You have two choices, you can use goxmr.click (you can audit and make sure there are no trackers and shit, if you find something let me know!) or host your own and make it work, that's it! The Sovereign Link-in-Bio for the Monero Ecosystem GGXMR is a digital identity platform and sovereign landing page, built with a Privacy-First philosophy. Lets any user create a public profile to centralize their networks, projects, and most importantly, receive donations in cryptos without relyin on centralized platforms that censor or track your data. 🛡️ Cutting-Edge Security and Authentication Zero Passwords, Zero Seeds: Uses WebAuthn (FIDO2). Forget vulnerable passwords or seed phrases. Log in with biometrics (FaceID/Fingerprint) or hardware keys (YubiKey). Total Hardening: Set up with Helmet security headers, strict Content Security Policy (CSP), and protection against brute force attacks and bots. No Admin Access: As a sovereign tool, no central database controlled by third parties. You're the only owner of your access. NOT EVEN I KNOW WHO'S USING IT 💰 Native Integration with Monero (XMR) Multi-Currency Ready: Visual and management support for XMR, BTC, LTC, ETH and more. 🎨 Cypherpunk Industrial Design Radical Aesthetic: Interface inspired by tactical terminals and industrial vibe with JetBrains Mono and Space Grotesk fonts. Total Customization: Users can upload their own banners and avatars, plus set accent colors and bios. QR Generator Pro: Dynamic and customizable QR code generator for instant payments. ⚙️ Technical Architecture (Sovereign Stack) Frontend: React + Vite + Tailwind CSS (Optimized for instant load). Backend: Node.js + Express (Robust and lightweight). Database: SQLite (Total portability; your "bank" is a simple file). Infrastructure: Optimized for secure server deploys and environments like Namecheap with reverse proxies. 🕊️ Open Source Philosophy 100% Transparent: Code is open and auditable. No Commissions: 0% fees on transactions. Donations go wallet to wallet without intermediaries. Anti-Censorship: Designed to be hosted by the user, eliminatin the risk of de-platforming. BTW PLEASE Keep in mind, that i am hosting this on my own server/hosting... not super powerful, bear with me while we upgrade this The future of digital identity in Monero is already sovereign! 🚀 #Monero #XMR #Privacy #Cypherpunk #OpenSource #WebAuthn #GoXMR if u like this, hit me with some xmr love on the site or bio addy... lets make it bigger! :p
English
11
7
50
4.5K
notafbihoneypot
notafbihoneypot@notafbihoneypot·
Monero One will soon be my main wallet
English
5
2
27
1K
Joe IO
Joe IO@Joe_IO·
@SlowBearDigger @notafbihoneypot Tremendous thanks. I would just ask to send me a list or report of your findings so I can fix anything that comes up first
English
1
0
2
19
It's FOSS
It's FOSS@Itsfoss·
I find it frustrating that none of these "guardians" of Linux and open source have reacted to the OS-level age verification law: - Linux Foundation - Open Source Initiative - Free Software Foundation - Software Freedom Conservancy
English
208
708
4.7K
108.6K
Lucas Ma
Lucas Ma@MaLucasBC·
@SlowBearDigger @HathorNetwork We have many malicious cases like this in immunefi. I'm setting up a victim group and collecting more details of the cases. Although it's just started, do you want to join us?
English
2
0
1
37
SlowBearDigger
SlowBearDigger@SlowBearDigger·
As I said back in February: I found a CRITICAL RCE in Hathor Desktop Wallet v0.34.0 (Immunefi #65067). @HathorNetwork closed it as “Out of Scope”. Immunefi banned me. After I kept spamming them via email + Discord they finally patched it quietly. No bounty. No thanks. No acknowledgement. Zero respect for whitehat work.
SlowBearDigger tweet mediaSlowBearDigger tweet mediaSlowBearDigger tweet media
English
2
1
17
1.3K
The Lunduke Journal
The Lunduke Journal@LundukeJournal·
Debian Project Leader Election Underway: Only 1 Candidate, & She's Anti "(Cis)Male" The only candidate to lead Debian Linux says her primary goal is to have "more women (both cis and trans), trans men, and genderqueer people."
English
77
48
416
17.1K
Intigriti
Intigriti@intigriti·
what's your most used bug bounty tool? 😎
English
37
0
66
13.4K
SlowBearDigger
SlowBearDigger@SlowBearDigger·
@PardonMyTake Well, meme is technically right, Venezuelans don't play American Football xD mostly Rugby and soccer/football
English
0
0
1
647
SlowBearDigger
SlowBearDigger@SlowBearDigger·
@immunefi Update, they're willing to pay low, for my finding, 1k aprox. i'll take it and close this chapter.
English
1
0
1
52
SlowBearDigger
SlowBearDigger@SlowBearDigger·
I also created a ISSUE on github describing this github.com/HathorNetwork/… So this just keeps being public and people know... To all the whitehat fellows, don't waste time on platforms like @immunefi because they don't care about you, and don't even think about sending reports to @HathorNetwork, they want you to work for free, closing your reports, fucking your reputation.
SlowBearDigger@SlowBearDigger

As I said back in February: I found a CRITICAL RCE in Hathor Desktop Wallet v0.34.0 (Immunefi #65067). @HathorNetwork closed it as “Out of Scope”. Immunefi banned me. After I kept spamming them via email + Discord they finally patched it quietly. No bounty. No thanks. No acknowledgement. Zero respect for whitehat work.

English
1
0
6
331
SlowBearDigger
SlowBearDigger@SlowBearDigger·
You're right, good intentions and no traditional "business model" for making money, it's not a VC startup chasing profits. But it has real utility, not only about big ass stonks and green graphs. theyre runnin' a guardian program supporting privacy advocates in communities worldwide where surveillance/censorship is heavy. Let's say is a good complement, i am super picky with crypto, but the fact they do good to community is enough to convince me, idk.
English
0
0
1
24
SlowBearDigger
SlowBearDigger@SlowBearDigger·
@monerify @vikrantnyc @firoorg @cakewallet It is a privacy coin, it was originally Zcoim, they use zkproof, and spark are their stealth addresses. Most importantly they’re doing wonders for communities all over the world where it’s needed.
English
1
0
1
49
SlowBearDigger
SlowBearDigger@SlowBearDigger·
@ertugrulphp @injective @immunefi They don't give a fuck, they only pay or help researchers when a smart contract or huge money is on risk. they're afraid of researchers exploiting the thing... i had a similar experience x.com/SlowBearDigger…
SlowBearDigger@SlowBearDigger

As I said back in February: I found a CRITICAL RCE in Hathor Desktop Wallet v0.34.0 (Immunefi #65067). @HathorNetwork closed it as “Out of Scope”. Immunefi banned me. After I kept spamming them via email + Discord they finally patched it quietly. No bounty. No thanks. No acknowledgement. Zero respect for whitehat work.

English
1
0
4
663
Ertugrul
Ertugrul@ertugrulphp·
The same kind of situation applies web2 as well on @injective. I found a valid issue, and the team actually fixed it. But after fixing it, they closed my report as “out of scope” According to @immunefi, if a reported vulnerability is fixed, the researcher should be rewarded+
Ertugrul tweet media
f4lc0n@al_f4lc0n

I Saved Injective's $500M. They Pay Me $50K. I like hunting bugs on @immunefi . I'm decent at it. - #1 — Attackathon | Stacks - #2 — Attackathon | Stacks II - #1 — Attackathon | XRPL Lending Protocol - 1 Critical and 1 High from bug bounties (not counting this one) Life was good. Then I found a Critical vulnerability in @injective . This vulnerability allowed any user to directly drain any account on the chain. No special permissions needed. Over $500M in on-chain assets were at risk. I reported it through Immunefi. The next day, a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity. Then — silence. For 3 months. No follow up. No technical discussion. Nothing. A few days ago, they notified me of their decision: $50K. The maximum payout for a Critical vulnerability in their bug bounty program is $500K. I disputed it. Silence again. No explanation for the reduced payout. No explanation for the 3 month ghost. No conversation at all. To be clear: the $50K has not been paid either. I've seen others share bad experiences with bug bounty payouts recently. I never thought it would happen to me. I can't force them to do the right thing. But I won't let this be forgotten. I will dedicate 10% of all my future bug bounty earnings to making sure this story stays visible — until Injective pays what I deserve. Full Technical Report: github.com/injective-wall…

English
4
5
90
8.8K
SlowBearDigger
SlowBearDigger@SlowBearDigger·
Full PoC (malicious SVG + fake metadata server) was done on a private testnet fork, 100% compliant. Real world attack: attacker just mints the NFT on mainnet with bad SVG URL. Victim receives airdrop > opens NFTs tab ? game over. Recommendations (that they ignored for weeks): nodeIntegration: false + contextIsolation: true + sandbox: true Sanitize NFT media (only https/ipfs, CSP) If you use Hathor Desktop Wallet > update NOW. Whitehats deserve better than this treatment!!! @HathorNetwork @HathorCommunity @immunefi What’s your take? Are you going to stay silent? while your whitehats gets treated like worthless trash?
English
0
1
4
195
SlowBearDigger
SlowBearDigger@SlowBearDigger·
Exact impact (matches their Critical tier, up to $20,000): Seed/private keys exfiltrated Forced outgoing txs (drain everything) Persistent malware/keylogger Silent compromise the moment the NFT List loads They patched ONLY the PDF rendering here: github.com/HathorNetwork/… Still no bounty. Still no “thank you”.
English
1
0
3
250