I went out for dinner and I took some endpoint
scarpino.dev
I went out for dinner and I took some endpoint
1–8 of 8 posts
Re: I went out for dinner and I took some endpoint
#2Yeah. No wonder people are selling this stuff.
Re: I went out for dinner and I took some endpoint
#3Re: I went out for dinner and I took some endpoint
#4I sure hope the backend uses prepared SQL statements.
Re: I went out for dinner and I took some endpoint
#5> They politely replied that they don’t provide bug bounties and the endpoints have been patched. Yeah. No wonder people are selling this stuff.
Oh, you don't do a bug bounty, and you say it's fixed when it clearly isn't? Okay, then it shouldn't be a problem if I publicly name, shame and provide a POC for everyone to see.
Though, I'm sure most people would just sell it to a vulnerability broker instead and make a quick buck.
Note: Such a platform I'm invisioning here would definitely be illegal. I'm aware.
Re: I went out for dinner and I took some endpoint
#6> They politely replied that they don’t provide bug bounties and the endpoints have been patched. Yeah. No wonder people are selling this stuff.
At this point I feel like an anonymous platform for publicly available bugs and vulns like this would be a good thing. Oh, you don't do a bug bounty, and you say it's fixed when it clearly isn't? Okay, then it shouldn't be a problem if I publicly name, shame and provide a POC for everyone to see. Though, I'm sure most people would just sell it to a vulnerability broker instead and make a quick buck. Note: Such a plat…
It’s like obligating companies to have a user feedback program.
Re: I went out for dinner and I took some endpoint
#7> They politely replied that they don’t provide bug bounties and the endpoints have been patched. Yeah. No wonder people are selling this stuff.
At this point I feel like an anonymous platform for publicly available bugs and vulns like this would be a good thing. Oh, you don't do a bug bounty, and you say it's fixed when it clearly isn't? Okay, then it shouldn't be a problem if I publicly name, shame and provide a POC for everyone to see. Though, I'm sure most people would just sell it to a vulnerability broker instead and make a quick buck. Note: Such a plat…
Some of them even have „autoshops“ where you can sell cc info to the system with price limit and buyers get matched like in a financial market with an orderbook. No shit