Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 3 days ago

We are at *twenty* hackerone submissions so for #curl far this year. Zero of them a confirmed vulnerability.

  • Copy link
  • Flag this post
  • Block
Volker Stolz
Volker Stolz
@fm_volker@mastodon.social replied  ·  activity timestamp 3 days ago

@bagder Wasn’t 📈exponential growth📈 what every project was hoping to achieve?!

Maybe it should be mandatory that the HackerOne submission must be done with `curl -X PUT … `, including BearerTokens/OAuth etc?

  • Copy link
  • Flag this comment
  • Block
JP Mens
JP Mens
@jpmens@mastodon.social replied  ·  activity timestamp 3 days ago

@bagder that screams for a new graph: "average number of hackerone submissions to the curl project per day". :)

  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp 3 days ago

@jpmens I foolish thought *per year* would be the appropriate time frame: https://curl.se/dashboard1.html#hackerone (the graph hasn't updated yet)

  • Copy link
  • Flag this comment
  • Block
Edvin Malinovskis
Edvin Malinovskis
@nCrazed@fd00.space replied  ·  activity timestamp 3 days ago

@bagder was there at least one "could be seen as a bug if you squint hard enough"?

  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp 3 days ago

@nCrazed yes, several of them were bugs in fact

  • Copy link
  • Flag this comment
  • Block
Lars Marowsky-Brée 😷
Lars Marowsky-Brée 😷
@larsmb@mastodon.online replied  ·  activity timestamp 3 days ago

@bagder Shld I submit a #hackerone submission for #curl, identifying hackerone as a DoS attack vector for the project, recommending depreciation?

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-beta.35 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct