Hacking, AppSec, and Bug Bounty newsletter
2017-06-09 | VDoS research, reflected XSS, and CVE-2016-10277
Friday, June 9
A few days ago, Brian Krebs posted, Following the Money Hobbled vDOS Attack-for-Hire Service, after NYU researchers wrote a paper on VDoS. It’s a nice casual Friday read as it follows his personal story of krebsonsecurity undergoing a DDoS attack as well as the larger story thread.
Reflected XSS on teavana.com (Locale-Change) [11 upvotes] - $250 bounty for this report to Starbucks by @inhibitor181. Injection made possible because the contents before the _CA were not validated.
Shopify GitHub Login and Password exposed all private source code might be available. [14 upvotes] - $1,500 bounty for this report to Shopify by @todayisnew.
You can see all the latest and greatest disclosures and bounties on www.hackerone.com/hacktivity
OTHER ARTICLES WE’RE READING
CVE-2016-10277: Vulns on Motorola devices
Troy Hunt laments that the web has become sucky
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: firstname.lastname@example.org
Get this email forwarded to you? Click here to subscribe to the Zero Daily
"Lordy, I hope there are tapes."