Hacking, AppSec, and Bug Bounty newsletter
2018-03-13| Creative DDoS attacks, ANY.RUN community edition, and 2 billion probable passwords
Tuesday, March 13
Stored XSS when you read emails. [13 upvotes] - $1,000 bounty for this report to Mail.Ru by @ras-it.
[serve] Directory listing and File access even when they have been set to be ignored. [10 upvotes] - no bounty for this report to Node.js third-party modules by @digitalwizard.
You can see all the latest and greatest disclosures and bounties on www.hackerone.com/hacktivity
TWEET OF THE DAY
So now there's a hardware pedal for improved text editing in Vim -@MasteringVim
OTHER ARTICLES WE’RE READING
ANY.RUN free community edition released
Newly updated list of top 2 billion probable passwords, sorted by probability
Mathy Vanhoef expands on the Wi-Fi Alliance press release announcing WPA3 with WPA3: technical details and discussion
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: firstname.lastname@example.org
Get this email forwarded to you? Click here to subscribe to the Zero Daily
I have found stored XSS when you read emails via style html tag.