Live data from Hacker News

Viewing profile — WUHANCLAN

WUHANCLAN

HN member
Joined
Mon, Feb 24, 2020, 5:19 PM UTC
HN karma
1
Public activity
10 items

About WUHANCLAN

No profile information was provided.

Recent public activity

  1. comment
    Comment #22422816

    Uh, some of these vulnerabilities are critical. And just because corporate signs up for a HackerOne bug bounty doesn't mean that the security engineers managing triage are happy ab…

  2. comment
    Comment #22412725

    Yeah I bet. It would be interesting to see how many U.S. DoD networks have been compromised with Burp Proxy.

  3. comment
    Comment #22410317

    HackerOne is complete fraud. They've got a super duper simple carrot before the horse business model which has thousands of kids beating up web apps for free. A valuable service fo…

  4. comment
    Comment #22410302

    No idea which one it was, or both. 23K isn't something to sneeze at though, and would be plenty of incentive for the folk at Portswigger to work with douchebags like whoever this s…

  5. comment
    Comment #22410298

    Bah there are several closed source plugins for Burp Proxy that are binary only and which constantly relay telemetry data back to Portswigger. I stopped using it for this exact rea…

  6. comment
    Comment #22410258

    The triage was escalated to Rob Fletcher and Uber's security liaison Lindsey Glovin. You're right, Portswigger was running a promo with HackerOne. After I submitted a couple of dif…

  7. comment
    Comment #22410195

    Either Uber lied about this guy discovering the flaw so they didn't have to pay me, or Burp Proxy is sending telemetry back to Portswigger with high value vulnerabilities being dis…

  8. comment
    Comment #22406098

    HackerOne can force their customers to pay, that's the entire point of their "guaranteed bounty" program, that's it's a guaranteed bounty! Even with a guaranteed bounty and a criti…

  9. comment
    Comment #22406078

    Bah no they aren't, HackerOne has a small collective of security testers that they consistently make awards to, over and over again. If you submit a critical vulnerability, magical…

  10. comment
    Comment #22406061

    HackerOne is complete garbage. I spent close to a month digging into Uber and compromised their m.uber.com mobile endpoint; they hemmed and hawed and then awarded the $25K to anoth…