Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
hypebot and 2 others boosted
Harry Sintonen
Harry Sintonen
@harrysintonen@infosec.exchange  ·  activity timestamp 3 days ago

I understand #curl project decision to stop the #bugbounty and leave #hackerone. The torrent of #AIslop has become unbearable.

https://github.com/curl/curl/pull/20312

I will continue to report vulnerabilities to the project whether it has a bug bounty or not.

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 3 days ago

We are at *twenty* hackerone submissions so for #curl far this year. Zero of them a confirmed vulnerability.

Lars Marowsky-Brée 😷
Lars Marowsky-Brée 😷
@larsmb@mastodon.online replied  ·  activity timestamp 3 days ago

@bagder Shld I submit a #hackerone submission for #curl, identifying hackerone as a DoS attack vector for the project, recommending depreciation?

  • Copy link
  • Flag this comment
  • Block
Harry Sintonen
Harry Sintonen
@harrysintonen@infosec.exchange  ·  activity timestamp 3 days ago

I understand #curl project decision to stop the #bugbounty and leave #hackerone. The torrent of #AIslop has become unbearable.

https://github.com/curl/curl/pull/20312

I will continue to report vulnerabilities to the project whether it has a bug bounty or not.

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg:// boosted
Harry Sintonen
Harry Sintonen
@harrysintonen@infosec.exchange  ·  activity timestamp 3 weeks ago

I'm submitting lovingly hand-crafted 100% organic reports to #curl #hackerone

  • Copy link
  • Flag this post
  • Block
Harry Sintonen
Harry Sintonen
@harrysintonen@infosec.exchange  ·  activity timestamp 3 weeks ago

I'm submitting lovingly hand-crafted 100% organic reports to #curl #hackerone

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 4 weeks ago

1. User complains to #hackerone that I named his *previous* name when he renamed himself to a silly name after I banned them in a #curl report filed back in October.

2. Hackerone asks me to respond on their support forum, on which I have no account. Grrr. I refuse to.

3. Replying to the hackerone email about this instead, I get a bounce saying they don't accept emails on support@hackerone ...

Kill me now.

(The user who submitted this report was going by the name "b4sh0ne" up until their last comment when they renamed to this new name. Unfortunately, the HackerOne interface does not properly show this. We banned the user nonetheless.)
(The user who submitted this report was going by the name "b4sh0ne" up until their last comment when they renamed to this new name. Unfortunately, the HackerOne interface does not properly show this. We banned the user nonetheless.)
(The user who submitted this report was going by the name "b4sh0ne" up until their last comment when they renamed to this new name. Unfortunately, the HackerOne interface does not properly show this. We banned the user nonetheless.)
  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-beta.35 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct