Affichage des articles dont le libellé est bug bounty. Afficher tous les articles
Affichage des articles dont le libellé est bug bounty. Afficher tous les articles

5 Years Old Boy Found Bug On XBOX







A five years old boy from San Diego named Kristoffer Von Hassel has found a bug on XBOX. He can log in into other's account by only pressing the SPACE button on the password column without entering any password. His father, shocked and feeling weird how can his son login into his account and play the game.

He told his father that he only entered the wrong password and then he pressed SPACE. With just that, he bypassed the auth. 



His father then reported this to the Microsoft. Kristoffer Von Hassel has been awarded from Microsoft for finding a bug in the XBOX.

SOURCE: Gila Hackers 

~ mardi 8 avril 2014 0 commentaires

Win $13,500 bounty to hack Kim Dotcom's Mega encryption


~ vendredi 1 février 2013 0 commentaires

ifixit.com Stored XSS Vulnerability


Well, it has been a long time, since i haven't posted any thing, i was a bit busy with my university exams, However, finally i managed to get some time to write something, Today i am sharing some of the vulnerabilites i found inside a popular website named "ifixit".

I found two XSS one was a Stored XSS and a second one was a Self XSS, However the Self-XSS could have been easily exploited by Clickjacking techniques as the page did not contain X-Frame options, Therefore the Self-XSS was also considered.
I have created a short POC of the Stored Cross Site Scripting vulnerability (XSS), I hope you enjoy it:

iFixit Stored Cross Site Scritping [Video POC]:

iFixit Self-XSS POC


For the above vulnerabilities, i was listed inside ifixit.com's responsible disclosure page:


Along with it, they also sent me two T-Shirts, some stickers and a 54 bit driver toolkit:


~ lundi 31 décembre 2012 0 commentaires

WOW! Paypal Sends Me 5000$ For A Command Execution Vulnerability


Update: 5000$ was the initial payment, Paypal payed another 5000$ which makes the total bug bounty of 10,000$ for the command execution vulnerability - 

PayPal Pays Me A Total Bounty Of 10,000 For The Command Execution Bug


Today when i logged into my Gmail account, I saw Paypal sent me 5000$  for my command execution bug i reported on one of it's subdomains, That's constituted a huge risk to the organization, since an attacker could have easily managed to execute any command on the server. Therefore the bug was extremely critical, however Paypal took more than 2 months to sort it out.
I cannot write more about the vulnerability per the terms of the bug bounty program.
Along with the command execution vulnerability, i was paid 500$ for an XSS vulnerability that i found on Paypal main domain, further more i was also paid for an information disclosure. So in total they sent me an amount of 6000$.

More than 20 of my bugs are still being validated by paypal.




Last week, i was offered by Paypal for a job as a Senior Pentester A.K.A SecurityNinja. kindly look at the screen shot below:


~ mardi 11 décembre 2012 0 commentaires