Hacking, AppSec, and Bug Bounty newsletter
2017-08-31 | Vulnerable pacemakers, ROP Emporium, and BSides Manchester recordings
Thursday, August 31
Request Hijacking Vulnerability in RubyGems 2.6.11 and earlier [8 upvotes] - $1,000 bounty for this report to RubyGems by @claudijd.
SSRF in https://imgur.com/vidgif/url [13 upvotes] - $2,000 bounty for this report to Imgur by @aesteral. @sumlac included this as one of the best-written reports he’s seen. Go and do likewise.
You can see all the latest and greatest disclosures and bounties on www.hackerone.com/hacktivity
OTHER ARTICLES WE’RE READING
Misconfigured customer support address leads to “Reply All” sharing of PII by Essential
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: firstname.lastname@example.org
Get this email forwarded to you? Click here to subscribe to the Zero Daily
...if exploited, could allow an unauthorized user (i.e. someone other than the patient's physician) to access a patient's device using commercially available equipment. This access could be used to modify programming commands to the implanted pacemaker, which could result in patient harm from rapid battery depletion or administration of inappropriate pacing.