Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
hackerpain
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
Q&A with one of the Richest Bug Bounty hunters who made over $2M in bounties
(savebreach.com)
1 points
by
hackerpain
5y ago
|
0 comments
2.
▲
by
hackerpain
6y ago
Using it since a decade, I faced bugs in the PGP encryption add on, they need to work on a lot of things to make it secure. This is my go-to Jabber client.
3.
▲
The embedded YouTube player told me what you were watching
(bugs.xdavidhu.me)
260 points
by
hackerpain
6y ago
|
104 comments
4.
▲
by
hackerpain
6y ago
How does this kind of vulnerability even remain, after code reviews? Is it hard to spot?
5.
▲
Linux Mint fixes screensaver bypass discovered by two kids
(zdnet.com)
16 points
by
hackerpain
6y ago
|
2 comments
6.
▲
Finding 0day to Hack Apple
(github.com)
5 points
by
hackerpain
6y ago
|
0 comments
7.
▲
by
hackerpain
6y ago
This bug was found by my friend. David has found many creative bugs and we worked on a project together :) Must say a quick thinker, and he's just 17 or 18.
8.
▲
by
hackerpain
6y ago
I think ReCaptcha has been like this since at least last 6 years. Are they copying research? https://www.youtube.com/watch?v=_RDXtILdkV0&persist_app=1&ap...
9.
▲
Breaking the Google Audio ReCAPTCHA with Google's Own Speech to Text API
(incolumitas.com)
2 points
by
hackerpain
6y ago
|
1 comments
10.
▲
by
hackerpain
6y ago
Please ignore
11.
▲
Ticketmaster Coughs Up $10M Fine After Hacking Rival Business
(threatpost.com)
3 points
by
hackerpain
6y ago
|
0 comments
12.
▲
by
hackerpain
6y ago
they haven't mentioned if an API (or, endpoint) is being DDoSed, just an incident update?
13.
▲
by
hackerpain
6y ago
Indeed.
14.
▲
Patch. Bypass. Repeat: Story of a Facebook Page Admin Disclosure Bug Worth $5000
(savebreach.com)
1 points
by
hackerpain
6y ago
|
0 comments
15.
▲
by
hackerpain
6y ago
We spent like 12 years trying to create a medium sized business in electronics and we were at that time in an era when mobile phones were still getting popular. It was a nascent stage of refurb smartphone industry but even then it was a ste
16.
▲
by
hackerpain
6y ago
That's quite hard because getting established in one trade in the industry itself takes a lot of time and effort.
17.
▲
Ask HN: How did you turn your failed business model into a successful venture?
1 points
by
hackerpain
6y ago
|
4 comments
18.
▲
by
hackerpain
6y ago
Install code-server ( https://github.com/cdr/code-server ) on a server, and using it in your phone's browser to develop small web apps (works well in landscape mode with 6 -6.7 inch phones) If you have a powerful pr
19.
▲
by
hackerpain
6y ago
I am sorry but that can ruin your career as its illegal. You can't sell or, trade vulnerabilities on live websites like Google as per the terms and conditions of the Google VRP (Responsible Disclosure policy) while it may seem unfair,
20.
▲
by
hackerpain
6y ago
docs.google.com didn't have X-Frame-Options: DENY nor a restrictive CSP so I think its a browser quirk (rather, a clever bypass) that works here. Also, the author had exploited a postMessage flaw which wasn't validating the host n
21.
▲
by
hackerpain
6y ago
Google VRP team has a tradition to reward 4 figure and 5 figure amounts to match 1337 or, L33T (Leet or, Elite). Example bounty amounts - $1337, $3133.7, $13337 and $31337
22.
▲
by
hackerpain
6y ago
this one technically requires some user interaction Anyway, in the past I found a way to takeover an organization account in Google cloud acquisition and they rewarded me $100, saying their "Panel" decided that, Google's VRP
23.
▲
Stealing private documents through a bug in Google Docs
(savebreach.com)
319 points
by
hackerpain
6y ago
|
138 comments
24.
▲
Silicon Valley's hunger problems grow during a time of record profits
(nbcnews.com)
1 points
by
hackerpain
6y ago
|
0 comments
25.
▲
Hacker Makes $2M in Bug Bounties
(savebreach.com)
5 points
by
hackerpain
6y ago
|
0 comments
26.
▲
I was able to view anyone’s private email and birthday on Instagram
(medium.com)
7 points
by
hackerpain
6y ago
|
0 comments
27.
▲
by
hackerpain
6y ago
SolarWinds earlier said the backdoored binaries were put into their servers in March 2020, and hinted that the breach happened in 2020 but seems like the breach happened way before. See related thread regarding the 2018 credentials leak -
28.
▲
Hackers last year conducted a 'dry run' of SolarWinds breach
(news.yahoo.com)
2 points
by
hackerpain
6y ago
|
1 comments
29.
▲
Czech Startup Founders Turn Billionaires Without VC Help
(bloomberg.com)
3 points
by
hackerpain
6y ago
|
2 comments
30.
▲
Ask HN: How ethical are pre-sales? Have you ever pre-sold a product?
3 points
by
hackerpain
6y ago
|
2 comments
More ›