ZERO DAILY

Hacking, AppSec, and Bug Bounty newsletter

2017-05-12 | Hacker heaven, Mozilla bug bounty, and Jaff ransomware

Friday, May 12

TGIF!

TOP STORY

HACKTIVITY

  • XSS in instacart.com/store/partner_recipe [7 upvotes] - $100 bounty for this report to Instacart by @karel_origin. The recipe_url parameter would reflect anything inside an href attribute, you only had to inject javascript:alert(1) and had to click on the link to execute the payload.

  • Clickjacking Vulnerability found on Yelp [4 upvotes] - $100 bounty for this report to Yelp by @hckyguy77. X-Frame-Options to SAME ORIGIN in HTTP headers; but exploit proves that not all pages were protected.

You can see all the latest and greatest disclosures and bounties on www.hackerone.com/hacktivity.

TWEET OF THE DAY

  • Dear Twitter: What do you think I do for a living? - @TheTarquin

OTHER ARTICLES WE’RE READING

ABOUT ZERO DAILY

Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.

Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?

Have a news tip / story to highlight? We’d love to hear about it. Email: zerodaily@hackerone.com

Get this email forwarded to you? Click here to subscribe to the Zero Daily

 

I didn’t have anything to put on it [toast] yesterday, so I put some grapes on it. It was weird.

Frans Rosen