GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Viss (viss@mastodon.social)'s status on Friday, 25-Apr-2025 05:00:32 JST Viss Viss

    another bug bounty, another story of 'closed wontfix', where they dont pay out and fix the bug anyway

    https://omarabid.com/hacker-one

    bug bounties were a mistake

    In conversation about 23 days ago from mastodon.social permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Friday, 25-Apr-2025 05:00:30 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to

      @Viss sounds about right :-/

      In conversation about 23 days ago permalink
    • Embed this notice
      Viss (viss@mastodon.social)'s status on Friday, 25-Apr-2025 05:00:31 JST Viss Viss
      in reply to

      this was... basically my experience with hackerone, the one time i used them.

      the first 'hack the pentagon' bug bounty. where I found two bluecoat proxies that were misconfigured and permit traffic natted into their lan from the wan.

      so i used proxychains, specified the wan addressess as http proxies, and contorted nmap to scan through it, and was getting tcp open/close hits from a 172 network inside what i was told later was "a training environment".

      zero payout, no credit
      but i got a coin?

      In conversation about 23 days ago permalink
    • Embed this notice
      Viss (viss@mastodon.social)'s status on Friday, 25-Apr-2025 05:00:31 JST Viss Viss
      in reply to

      im told it was the second-worst finding of the entire program, so youd think that would count for something, but oh well.

      been sour on bugbounties since then. they seem to work on the 'carnival principle' - where a tiny handful of folks get MASSIVE PAYOUTS, and they gloat and brag about them, and thats the sorta marketing engine that keeps people trying them. most folks get peanuts, or nothing.

      In conversation about 23 days ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Friday, 25-Apr-2025 05:09:24 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Paul_IPv6

      @Viss @paul_ipv6 lolsob

      In conversation about 23 days ago permalink
    • Embed this notice
      Paul_IPv6 (paul_ipv6@infosec.exchange)'s status on Friday, 25-Apr-2025 05:09:25 JST Paul_IPv6 Paul_IPv6
      in reply to
      • Ryan Castellucci :nonbinary_flag:

      @Viss @ryanc

      one of my pet peeves was the seemingly endless parade of congress-critters on CSPAN getting up to talk about something technical and starting with "i don't know how any of this techy stuff works at all but i think we should...".

      no one goes to a "doctor" who starts with "i have no idea of how diseases or the body works and have no medical expertise but i think we should...".

      In conversation about 23 days ago permalink
    • Embed this notice
      Viss (viss@mastodon.social)'s status on Friday, 25-Apr-2025 05:09:25 JST Viss Viss
      in reply to
      • Paul_IPv6
      • Ryan Castellucci :nonbinary_flag:

      @paul_ipv6 @ryanc rfk does

      In conversation about 23 days ago permalink
    • Embed this notice
      Viss (viss@mastodon.social)'s status on Friday, 25-Apr-2025 05:09:26 JST Viss Viss
      in reply to
      • Ryan Castellucci :nonbinary_flag:

      @ryanc so infuriatingly stupid. people who dont know how to computer shouldnt fucking be allowed to touch computers. not unless its to learn how to computer, and that would be on training computers.

      the beatings will continue as long as the head of the cia uses an aol email address and politicians gloat about never reading emails and being complete nontechnical troglodytes

      In conversation about 23 days ago permalink
    • Embed this notice
      Wulfy (n_dimension@infosec.exchange)'s status on Friday, 25-Apr-2025 05:36:29 JST Wulfy Wulfy
      in reply to
      • Paul_IPv6
      • Ryan Castellucci :nonbinary_flag:

      @paul_ipv6 @Viss @ryanc

      Internet is a series of pipes

      In conversation about 23 days ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Friday, 25-Apr-2025 05:36:29 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to
      • Paul_IPv6
      • Wulfy

      @n_dimension @paul_ipv6 @Viss one time, on the way to hacker camp, I saw a big truck carrying a series of tubes

      In conversation about 23 days ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.