Hacking, AppSec, and Bug Bounty newsletter
2018-06-05 | Filedescriptor’s RPO XSS on Google, the Riskiest US states for cybercrime, and Calm App’s soothing GDPR meditations
Tuesday, June 5
“72 percent of residents in Florida, Wyoming, Montana, New Mexico, and Illinois said they share their passwords with others”. Webroot published survey results on the riskiest states for cybercrime in America .
TWEET OF THE DAY
How to make $80k in one day: Blockchain bugs. - @jon_bottarini
OTHER ARTICLES WE’RE READING
A coalition of groups including Verified Voting and Common Cause published a new toolkit for local election officials to follow on securing voting machines. Paper, people! Paper ballots are the new new.
Ticketfly breach affected 26 million users reports Motherboard, citing research by Troy Hunt.
Filedescriptor’s RPO XSS on Google write up (see the end of the writeup for additional recommended reading on RPO exploitation techniques)
Meditation app Calm soothes you with audio highlights from the GDPR legislation
The NSA just released security posters from the 1950s and 1960s and they’re beyond amazing.
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: firstname.lastname@example.org
Get this email forwarded to you? Click here to subscribe to the Zero Daily
One of the more alarming fndings, throughout the information gathering stage, was how many
projects are publicly publishing secrets on the likes of GitHub. As well as a secret utilising a high
level of entropy, it's equally as important that the secret not be leaked.
HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited. As the contemporary alternative to traditional penetration testing, our bug bounty program solutions encompass vulnerability assessment, crowdsourced testing and responsible disclosure management. Discover more about our security testing solutions or Contact Us today.