4 ms·
GitHub Access Token Exposure
- Pyrobyte 2y agoJust a pretty nice exploit, he got paid 50,000 as a bounty for a simple piece of code with critical impacts.
- skilled 2y agoTitle is misleading and it should have (2021) in it too. Relevant, Compsci student walks off with $50,000 after bug bounty report blows gaping hole in Shopify software repos (https://www.theregister.com/2021/07/27/shopify_bug_bounty_payout/ https://www.theregister.com/2021/07/27/shopify_bug_bounty_pa...)
- Pyrobyte 2y agoYes sorry I saw it and literally clicked the share button to hacker news so I expected it to follow the right submission rules