2 ms·
Before this reaches a level rehashing the old "sell it on the blackmarket", I would like to clarify an issue here. The policy change that occurred for Sean (th
by phwd 11y ago
Before this reaches a level rehashing the old "sell it on the blackmarket", I would like to clarify an issue here.
The policy change that occurred for Sean (the person the OP is using for his argument) was that Uber had clarified a change, without any clear notification. I blame the HackerOne Platform here, there is no way to send a notice of scope unless the program owner manually appends it at the top (in the case of yahoo https://hackerone.com/yahoo https://hackerone.com/yahoo)
So its scope (https://hackerone.com/uber https://hackerone.com/uber) changed from in scope
"Exposed Administrative Panels and Ports (Excluding OneLogin)"
to
"Exposed Administrative Panels that don't require login credentials"
With ports moved to out of scope unless,
"Open ports without an accompanying proof-of-concept demonstrating vulnerability"
I cannot speak for the OP and the validity of his XSS bug however.