Did I just win?
31–40 of 140 posts
Re: Did I just win?
#32It's not clever to hack something that you can socially engineer, and that should be hacking 101. Clever win.
Re: Did I just win?
#33Another way to win this bounty would be to share some code with the string BackdoorPoCTwitter with the same color as the page background. If he copy and paste the code it could work. ^^
Re: Did I just win?
#34Can someone link to context? Without it, I don't see why this is even posted here.
@Sc00bzT > @DefuseSec You should put this challenge on your website.
@DefuseSec > @Sc00bzT Good idea, added it to this page: https://defuse.ca/security-contact-vulnerability-disclosure....
@Sc00bzT > @DefuseSec Did I just win?
@DefuseSec > @Sc00bzT FUCK. What's your paypal/bitcoin?
[See https://github.com/defuse/defuse.ca/commit/4770ad5c9d4851d40... for commit.]
Re: Did I just win?
#35Can someone link to context? Without it, I don't see why this is even posted here.
Re: Did I just win?
#36Another way to win this bounty would be to share some code with the string BackdoorPoCTwitter with the same color as the page background. If he copy and paste the code it could work. ^^
The only way that would work is if he committed copy/pasted code without reviewing it first, which is highly unlikely. Or at least I would hope it is, given that he's actually challenged people to do this.
Also, if he validated the code before copy and paste, the string would be invisible.
Re: Did I just win?
#37It's not clever to hack something that you can socially engineer, and that should be hacking 101. Clever win.
Re: Did I just win?
#38Re: Did I just win?
#39Re: Did I just win?
#40Social Engineering is not accepted in most hacking contests.
This was not a hacking contest. The specific request was: "I'll give $100 USD to anyone who can trick me into inserting the string "BackdoorPoCTwitter" into a release of any of my software projects." Emphasis on the "trick me".