Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
daniel:// stenberg:// boosted
๐•‚๐šž๐š‹๐š’๐š”โ„™๐š’๐šก๐šŽ๐š•
๐•‚๐šž๐š‹๐š’๐š”โ„™๐š’๐šก๐šŽ๐š•
@kubikpixel@chaos.social  ยท  activity timestamp 2 days ago

ยปcurl โ€” Projekt beendet Bug-Bounty-Programm:
curl-Maintainer @bagder hat das Ende des Bug-Bounty-Programms angekรผndigt. Unbrauchbare KI-Meldungen nahmen wohl รผberhand.ยซ

Ach was die KI ist kรผnstlich aber nicht intelligent oder was nun?!?? Ich bin sogar der Meinung, dass dies was die KI angeht noch das rel. kleinste "Problem" ist. Schade dass deswegen das curl Bug-Bounty aufgelรถst wird.

๐Ÿง‘โ€๐Ÿ’ป https://www.heise.de/news/curl-Projekt-beendet-Bug-Bounty-Programm-11142345.html?wt_mc=rss.red.ho.ho.rdf.beitrag.beitrag

#curl #ki #bugbounty #unbrauchbar #ai #uberhang #ausserkontrolle #it #ittools

Security

curl: Projekt beendet Bug-Bounty-Programm

curl-Maintainer Daniel Stenberg hat das Ende des Bug-Bounty-Programms angekรผndigt. Unbrauchbare KI-Meldungen nahmen wohl รผberhand.
  • Copy link
  • Flag this post
  • Block
๐•‚๐šž๐š‹๐š’๐š”โ„™๐š’๐šก๐šŽ๐š•
๐•‚๐šž๐š‹๐š’๐š”โ„™๐š’๐šก๐šŽ๐š•
@kubikpixel@chaos.social  ยท  activity timestamp 2 days ago

ยปcurl โ€” Projekt beendet Bug-Bounty-Programm:
curl-Maintainer @bagder hat das Ende des Bug-Bounty-Programms angekรผndigt. Unbrauchbare KI-Meldungen nahmen wohl รผberhand.ยซ

Ach was die KI ist kรผnstlich aber nicht intelligent oder was nun?!?? Ich bin sogar der Meinung, dass dies was die KI angeht noch das rel. kleinste "Problem" ist. Schade dass deswegen das curl Bug-Bounty aufgelรถst wird.

๐Ÿง‘โ€๐Ÿ’ป https://www.heise.de/news/curl-Projekt-beendet-Bug-Bounty-Programm-11142345.html?wt_mc=rss.red.ho.ho.rdf.beitrag.beitrag

#curl #ki #bugbounty #unbrauchbar #ai #uberhang #ausserkontrolle #it #ittools

Security

curl: Projekt beendet Bug-Bounty-Programm

curl-Maintainer Daniel Stenberg hat das Ende des Bug-Bounty-Programms angekรผndigt. Unbrauchbare KI-Meldungen nahmen wohl รผberhand.
  • Copy link
  • Flag this post
  • Block
hypebot and 2 others boosted
Harry Sintonen
Harry Sintonen
@harrysintonen@infosec.exchange  ยท  activity timestamp 4 days ago

I understand #curl project decision to stop the #bugbounty and leave #hackerone. The torrent of #AIslop has become unbearable.

https://github.com/curl/curl/pull/20312

I will continue to report vulnerabilities to the project whether it has a bug bounty or not.

  • Copy link
  • Flag this post
  • Block
Harry Sintonen
Harry Sintonen
@harrysintonen@infosec.exchange  ยท  activity timestamp 4 days ago

I understand #curl project decision to stop the #bugbounty and leave #hackerone. The torrent of #AIslop has become unbearable.

https://github.com/curl/curl/pull/20312

I will continue to report vulnerabilities to the project whether it has a bug bounty or not.

  • Copy link
  • Flag this post
  • Block
Frรฉdรฉric Jacobs boosted
Konstantin :C_H:
Konstantin :C_H:
@kpwn@infosec.exchange  ยท  activity timestamp 3 weeks ago

#CVECrowd, your go-to place for #CVE discussions on the Fediverse and Bluesky, now supports email alerts.

https://cvecrowd.com

Here's how it works:

- You define one or more alert keywords
- Keywords are matched against vendor, product, and package names from official CVE data
- If a post mentions a CVE that matches one of your keywords, you receive an email notification

Read more below ๐Ÿงต

#Pentesting #AppSec #InfoSec #CyberSecurity #BugBounty #Hacking

  • Copy link
  • Flag this post
  • Block
Konstantin :C_H:
Konstantin :C_H:
@kpwn@infosec.exchange  ยท  activity timestamp 3 weeks ago

#CVECrowd, your go-to place for #CVE discussions on the Fediverse and Bluesky, now supports email alerts.

https://cvecrowd.com

Here's how it works:

- You define one or more alert keywords
- Keywords are matched against vendor, product, and package names from official CVE data
- If a post mentions a CVE that matches one of your keywords, you receive an email notification

Read more below ๐Ÿงต

#Pentesting #AppSec #InfoSec #CyberSecurity #BugBounty #Hacking

  • Copy link
  • Flag this post
  • Block
Em :official_verified: boosted
BobDaHacker ๐Ÿณ๏ธโ€โšง๏ธ | NB
BobDaHacker ๐Ÿณ๏ธโ€โšง๏ธ | NB
@bobdahacker@infosec.exchange  ยท  activity timestamp 3 weeks ago

๐Ÿ”“ Found critical vulns in Taimi (LGBTQ+ dating app) - all fixed, $10k bounty

What I found:

  • "Expiring" videos didn't expire, URLs stayed valid forever
  • Decrement attachment ID = anyone's private videos
  • Location feature bypassed photo permission checks (why upload a map preview image through the photo system??)
  • Fake system messages (made a Raid Shadow Legends sponsorship lol)

The good news: Taimi actually handled this right. Fast response, $10k bounty, everything fixed quickly. No lawyers, no threats.

This is how disclosure should work. Take notes, Lovense.

Full writeup: https://bobdahacker.com/blog/taimi-idor

#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Taimi #DatingApp #Security #Privacy #CyberSecurity #LGBTQ

Taimi: Finding Everyone's Private Photos Was Easy, But So Was Getting Paid

How I found critical IDOR vulnerabilities in Taimi that exposed
  • Copy link
  • Flag this post
  • Block
BobDaHacker ๐Ÿณ๏ธโ€โšง๏ธ | NB
BobDaHacker ๐Ÿณ๏ธโ€โšง๏ธ | NB
@bobdahacker@infosec.exchange  ยท  activity timestamp 3 weeks ago

๐Ÿ”“ Found critical vulns in Taimi (LGBTQ+ dating app) - all fixed, $10k bounty

What I found:

  • "Expiring" videos didn't expire, URLs stayed valid forever
  • Decrement attachment ID = anyone's private videos
  • Location feature bypassed photo permission checks (why upload a map preview image through the photo system??)
  • Fake system messages (made a Raid Shadow Legends sponsorship lol)

The good news: Taimi actually handled this right. Fast response, $10k bounty, everything fixed quickly. No lawyers, no threats.

This is how disclosure should work. Take notes, Lovense.

Full writeup: https://bobdahacker.com/blog/taimi-idor

#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Taimi #DatingApp #Security #Privacy #CyberSecurity #LGBTQ

Taimi: Finding Everyone's Private Photos Was Easy, But So Was Getting Paid

How I found critical IDOR vulnerabilities in Taimi that exposed
  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ยท  activity timestamp 2 months ago

$1900 Bug Bounty to Fix the Lenovo Legion Pro 7 16IAX10H's Speakers on Linux

https://github.com/nadimkobeissi/16iax10h-linux-sound-saga

#HackerNews #BugBounty #Lenovo #LegionPro7 #Linux #Speakers #Fix #SoundSaga

  • Copy link
  • Flag this post
  • Block
halcyโ€‹ :icosahedron: and 1 other boosted
Bรกlint Magyar
Bรกlint Magyar
@balint@mastodon.social  ยท  activity timestamp 5 months ago

Here's my new article on how I escalated a CSS injection to remote code execution on a Google app. Enjoy!

https://bm.gy/gwdrce3

#Cybersecurity#InfoSec#BugBounty#IndieSec#Vulnerability

  • Copy link
  • Flag this post
  • Block
Bรกlint Magyar
Bรกlint Magyar
@balint@mastodon.social  ยท  activity timestamp 5 months ago

Here's my new article on how I escalated a CSS injection to remote code execution on a Google app. Enjoy!

https://bm.gy/gwdrce3

#Cybersecurity#InfoSec#BugBounty#IndieSec#Vulnerability

  • Copy link
  • Flag this post
  • Block
theruran ๐Ÿ’ป ๐ŸŒ :cereal_killer: boosted
BobDaHacker ๐Ÿณ๏ธโ€โšง๏ธ | NB
BobDaHacker ๐Ÿณ๏ธโ€โšง๏ธ | NB
@bobdahacker@infosec.exchange  ยท  activity timestamp 5 months ago

Hacked Monster Energy ๐Ÿ’€

They think their customers are "lower income Caucasian males (skews Hispanic)" and left their ENTIRE file system exposed.

https://bobdahacker.com/blog/monster-energy

#InfoSec#Security#DataBreach#MonsterEnergy#Vulnerability#CyberSecurity#ResponsibleDisclosure#BugBounty

  • Copy link
  • Flag this post
  • Block
BobDaHacker ๐Ÿณ๏ธโ€โšง๏ธ | NB
BobDaHacker ๐Ÿณ๏ธโ€โšง๏ธ | NB
@bobdahacker@infosec.exchange  ยท  activity timestamp 5 months ago

Hacked Monster Energy ๐Ÿ’€

They think their customers are "lower income Caucasian males (skews Hispanic)" and left their ENTIRE file system exposed.

https://bobdahacker.com/blog/monster-energy

#InfoSec#Security#DataBreach#MonsterEnergy#Vulnerability#CyberSecurity#ResponsibleDisclosure#BugBounty

  • Copy link
  • Flag this post
  • Block
Dane ๐Ÿ‡ฎ๐Ÿ‡ช โ˜ฎ๏ธ๐Ÿ•‰๏ธโš›๏ธโ˜ธ๏ธ boosted
BobDaHacker ๐Ÿณ๏ธโ€โšง๏ธ | NB
BobDaHacker ๐Ÿณ๏ธโ€โšง๏ธ | NB
@bobdahacker@infosec.exchange  ยท  activity timestamp 6 months ago

Found critical vulns in Lovense (the biggest sex toy company) affecting 11M+ users. They ignored researchers for 2+ years, then fixed in 2 days after public exposure. ๐Ÿคฆ

What I found:
- Email disclosure via XMPP (usernameโ†’email)
- Auth bypass (emailโ†’account takeover, no password)

History of ignoring researchers:
- 2022: Someone else reports XMPP email leak, ignored
- Sept 2023: Krissy reports account takeover + different email leak via HTTP API, paid only $350
- 2024: Another person reports XMPP email leak AND Account Takeover vuln, offered 2 free sex toys (accepted for the meme)
- March 2025: I report account takeover + XMPP email leak, paid $3000 (after pushing for critical)
- Told me fix for email vuln needs 14 months because "legacy support" > user security (had 1-month fix ready)
- July 28: I go public
- July 30: Both fixed in 48 hours

Same bugs, different treatment. They lied to journalists saying it was fixed in June, tried to get me banned from HackerOne after giving permission to disclose.

News covered it but my blog has the full technical details:
https://bobdahacker.com/blog/lovense-still-leaking-user-emails/

Edit: If you have Twitter Please retweet this. This guy was one of the CO Founders of Lovense and got kicked out like how Mark Zuckerburg from Facebook did to one of his Co-Founders
https://x.com/LovenseDispute/status/1879155775865589995

#InfoSec#BugBounty#ResponsibleDisclosure#Security#Vulnerability#IoT #cybersecurity

  • Copy link
  • Flag this post
  • Block
BobDaHacker ๐Ÿณ๏ธโ€โšง๏ธ | NB
BobDaHacker ๐Ÿณ๏ธโ€โšง๏ธ | NB
@bobdahacker@infosec.exchange  ยท  activity timestamp 6 months ago

Found critical vulns in Lovense (the biggest sex toy company) affecting 11M+ users. They ignored researchers for 2+ years, then fixed in 2 days after public exposure. ๐Ÿคฆ

What I found:
- Email disclosure via XMPP (usernameโ†’email)
- Auth bypass (emailโ†’account takeover, no password)

History of ignoring researchers:
- 2022: Someone else reports XMPP email leak, ignored
- Sept 2023: Krissy reports account takeover + different email leak via HTTP API, paid only $350
- 2024: Another person reports XMPP email leak AND Account Takeover vuln, offered 2 free sex toys (accepted for the meme)
- March 2025: I report account takeover + XMPP email leak, paid $3000 (after pushing for critical)
- Told me fix for email vuln needs 14 months because "legacy support" > user security (had 1-month fix ready)
- July 28: I go public
- July 30: Both fixed in 48 hours

Same bugs, different treatment. They lied to journalists saying it was fixed in June, tried to get me banned from HackerOne after giving permission to disclose.

News covered it but my blog has the full technical details:
https://bobdahacker.com/blog/lovense-still-leaking-user-emails/

Edit: If you have Twitter Please retweet this. This guy was one of the CO Founders of Lovense and got kicked out like how Mark Zuckerburg from Facebook did to one of his Co-Founders
https://x.com/LovenseDispute/status/1879155775865589995

#InfoSec#BugBounty#ResponsibleDisclosure#Security#Vulnerability#IoT #cybersecurity

  • Copy link
  • Flag this post
  • Block
๐•‚๐šž๐š‹๐š’๐š”โ„™๐š’๐šก๐šŽ๐š•
๐•‚๐šž๐š‹๐š’๐š”โ„™๐š’๐šก๐šŽ๐š•
@kubikpixel@chaos.social  ยท  activity timestamp 6 months ago

ยปWegen KI-Schrott โ€“ Curl-Entwickler erwรคgt Ende der Bug-Bounty-Prรคmien:
Minderwertige Bug-Reports belasten Open-Source-Entwickler immer stรคrker. Curl-Maintainer @bagder zieht nun radikale MaรŸnahmen in Erwรคgung.ยซ

Lasst mich raten, IT-Konzerne belasten Developer von Werkzeugen, die sie Tรคglich selber nutzen. Was ist daran intelligent oder gar kรผnstlerisch?
/s

๐Ÿคจ https://www.golem.de/news/wegen-ki-schrott-curl-entwickler-erwaegt-ende-der-bug-bounty-praemien-2507-198123.html

#curl #opensource #web #internet #ai #ki #belastung #entwickler #kischrott #bugbounty

  • Copy link
  • Flag this post
  • Block
Cory Doctorow boosted
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ยท  activity timestamp 6 months ago

Death by a thousand slops

https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-slops/

#curl#AI #bugbounty

  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About ยท Code of conduct ยท Privacy ยท Users ยท Instances
Bonfire social ยท 1.0.1-beta.35 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct