Hacking, AppSec, and Bug Bounty newsletter
2017-11-03 | Mobile Pwn2Own results, KRACK IBB bounty, and Krebs isn’t happy
Friday, November 3
Today, we highlight multiple Hacktivity reports in a special edition of Zero Daily.
Key Reinstallation Attacks: Breaking WPA2 by forcing nonce reuse [37 upvotes] - $25,000 bounty for this report to Internet Bug Bounty by @vanhoefm.
[CRITICAL] Full account takeover using CSRF [28 upvotes] $5,040 bounty for this report to Twitter by @yipman.
Saying goodbye to HackerOne and Gratipay [46 upvotes] - no bounty but lots and lots of love. Tip of the cap to you @edio.
You can see all the latest and greatest disclosures and bounties on www.hackerone.com/hacktivity
TWEET OF THE DAY
Bug bounty protip: stop your browser snitching on your XSS findings with a proxy match/replace rule - @albinowax
OTHER ARTICLES WE’RE READING
Krebs isn’t happy: Equifax reopens salary lookup service with new “security enhancements”
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: firstname.lastname@example.org
Get this email forwarded to you? Click here to subscribe to the Zero Daily
We're looking for a junior developer with the experience of a senior developer for the salary of an intern.