Hacking, AppSec, and Bug Bounty newsletter
2018-02-15 | AMA with Orange, NIST’s IoT report, and DO NOT TEXT ME
Thursday, February 15
DO NOT TEXT ME: Better check those Facebook comms settings before implementing 2FA. Or just use a code generator app or U2F key.
Changing details of other users profile using UUID (IDOR) [9 upvotes] - $1,200 bounty for this report to Showmax by @ehsahil
Leaking password reset link on referrer header [3 upvotes] - no bounty for this report to Coursera by @flex0geek.
You can see all the latest and greatest disclosures and bounties on www.hackerone.com/hacktivity
OTHER ARTICLES WE’RE READING
Few standards, low adoption: NIST’s IoT report
Zonksec teaches you about phishing with google analytics
$7.5k bounty awarded by Google for a Google Services Management bug
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: email@example.com
Get this email forwarded to you? Click here to subscribe to the Zero Daily
The top risk organizations face today is a lack of experienced staff to monitor and help protect networks from cybercrime