Live data from Hacker News

Viewing profile — innoying

innoying

HN member
Joined
Sat, Sep 24, 2011, 7:31 PM UTC
HN karma
338
Public activity
56 items

About innoying

I find bugs and exploit them. Sometimes for money, mainly for T-Shirts - https://bored.engineer/

Recent public activity

  1. comment
    Comment #48213134

    If you own a GitHub organization and are looking for what changes/controls you can apply to reduce the risk/impact of PAT token exfiltration (and subsequent abuse) like what occurr…

  2. story
  3. comment
    Comment #46611723

    The newer global node IDs (which can be forced via the 'X-Github-Next-Global-ID' header [1]) have a prefix indicating the "type" of object delimited by an underscore, then a base64…

  4. story
  5. comment
    Comment #24647856

    CodeQL is based on an existing product from a company called Semmle which GitHub acquired in late 2019 [1] They have been part of GitHub for barely a year so it's not too surprisin…

  6. comment
    Comment #18511474

    If anyone is interested in even more data than Artem released, I did a similar experiment based off Artem's work except with a couple hundred domains and with TLS certificates for …

  7. comment
    Comment #13452107

    Why does this comment appear on every bug bounty HN thread? Straight from the horse's mouth [0]: The black market is very unlikely to be a place you could sell a bug in a specific …

  8. comment
    Comment #13452031

    Technically they did employ some DNS validation. You had to setup a MX record to point to SendGrid before you could add the domain to your account. The problem was in order to send…

  9. comment
    Comment #13451971

    I do not believe the author circulated this report to multiple companies, however once it was made public a number of other reporters in the community did and continued to iterate …

  10. comment
    Comment #13451959

    I believe they did retroactively search for accounts. Source: I had a number of accounts banned when testing different iterations of this bug.

  11. comment
    Comment #13302590

    But that's not what happened here at all. Bitbucket has responded explaining why this (self-inflicted) bug exists (a security decision in an underlying framework) and deferred to t…

  12. comment
    Comment #13302541

    I think you're misunderstanding the attack scenario here: > Anyway, if the browser is connecting via port 80, the MITM can just use a transparent http->https proxy to rewrite the r…

  13. comment
    Comment #13204443

    Hi "FBSecuritySux", I'm not a member of the Facebook security team, but I work in the industry and your comment frustrates me. I can understand criticizing companies for poor secur…

  14. story
  15. comment
    Comment #12437703

    It's been private (invite-only) for about 2 years, they went public today.

  16. comment
    Comment #12395334

    It's not an "easy fix", there could be (and probably are) thousands of different endpoints that can be redirected to after login, whitelisting all of those just doesn't make sense.…

  17. comment
    Comment #12395329

    I totally agree. I don't even see how the impact is even more than the open-redirects which already exist. You could do this exact same exploit against tons of providers (Facebook,…

  18. comment
    Comment #8828422

    Or like any compiled language they can just grab a binary: https://github.com/github/hub/releases

  19. story
  20. story
  21. story
  22. story
  23. comment
    Comment #7774861

    Plausible deniability.

  24. comment
    Comment #7728905

    Somewhat related, but I made a small site to help the average internet "user" understand what net neutrality is and why it's important: http://net-neutrality.io/ I'm not quite sure…

  25. story