Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rwestergren
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
rwestergren
8y ago
Apparently unpopular opinion: an internally-discovered vulnerability with no evidence of abuse is not a breach and does not require public disclosure.
32.
▲
XSS Vulnerabilities in Multiple iFrame Busters Affecting Top Tier Sites
(randywestergren.com)
1 points
by
rwestergren
8y ago
|
0 comments
33.
▲
Compromising OpenDrive's Cloud Storage Accounts – Or How Not to Do Session Mgmt
(randywestergren.com)
1 points
by
rwestergren
8y ago
|
0 comments
34.
▲
Persistent XSS in PNC’s Secure Email System
(randywestergren.com)
2 points
by
rwestergren
9y ago
|
0 comments
35.
▲
Reverse Engineering the OBi200 Google Voice Appliance: Part 3
(randywestergren.com)
1 points
by
rwestergren
9y ago
|
0 comments
36.
▲
Reverse Engineering the OBi200 Google Voice Appliance: Part 1
(randywestergren.com)
2 points
by
rwestergren
9y ago
|
0 comments
37.
▲
Bright City: A Highly Insecure Police and Municipal Government App
(randywestergren.com)
2 points
by
rwestergren
9y ago
|
0 comments
38.
▲
XSS Over SMS: Hacking Text Messages in Verizon Messages
(randywestergren.com)
1 points
by
rwestergren
9y ago
|
0 comments
39.
▲
by
rwestergren
10y ago
Appreciate the feedback! My point on the price concern was that the app was not developed solely for my county, it was resold to multiple customers - at least 2,000 according to the link I posted in another comment. I'm not sure what o
40.
▲
by
rwestergren
10y ago
They have at least 2K customers according to this: http://www.king5.com/tech/schools-businesses-emergency-respo... Not sure what each customer was charged, but it sounds like the app/system was resold to individua
41.
▲
Rave Panic Button: Vulnerabilities in a Nationwide Emergency Alert System
(randywestergren.com)
85 points
by
rwestergren
10y ago
|
27 comments
42.
▲
Persistent XSS in Verizon’s Webmail Client
(randywestergren.com)
1 points
by
rwestergren
10y ago
|
0 comments
43.
▲
Legislating Vulnerability Disclosure Programs into State-Level Government
(randywestergren.com)
1 points
by
rwestergren
10y ago
|
0 comments
44.
▲
Critical Vulnerability Compromising Verizon Email Accounts (Again)
(randywestergren.com)
4 points
by
rwestergren
10y ago
|
0 comments
45.
▲
by
rwestergren
11y ago
Interesting to note that a number of these sites were recently also serving ads vulnerable to XSS: http://randywestergren.com/widespread-xss-vulnerabilities-ad...
46.
▲
Widespread XSS Vulnerabilities in Ad Code Affecting Top Tier Publishers
(randywestergren.com)
7 points
by
rwestergren
11y ago
|
2 comments
47.
▲
Hijacking Verizon FiOS Accounts [FIXED]
(randywestergren.com)
3 points
by
rwestergren
11y ago
|
0 comments
48.
▲
Running a Hidden Tor Service with Docker Compose
(randywestergren.com)
4 points
by
rwestergren
11y ago
|
0 comments
49.
▲
Reverse Engineering the Yik Yak Android App
(randywestergren.com)
8 points
by
rwestergren
11y ago
|
0 comments
50.
▲
Cutting the Lights: Vulnerabilities in a Billboard Lighting System
(randywestergren.com)
45 points
by
rwestergren
11y ago
|
5 comments
51.
▲
United Airlines Bug Bounty: An experience in reporting a serious vulnerability
(randywestergren.com)
164 points
by
rwestergren
11y ago
|
72 comments
52.
▲
Attacking Real Estate Showings in ShowingTime
(randywestergren.com)
3 points
by
rwestergren
11y ago
|
0 comments
53.
▲
by
rwestergren
11y ago
I understand what you mean, but an attacker wouldn't be able to decrypt during a MiTM attack since SSL is being used -- regardless of cert pinning. An effect of pinning is losing the ability to perform a self MiTM to decrypt traffic; t
54.
▲
by
rwestergren
11y ago
I was pretty sure of the 3rd party integration, but still am not sure why they're checking if the user's device is rooted. I suppose for payment processing, they consider it a security risk?
55.
▲
Reverse Engineering the Subway Android App
(randywestergren.com)
39 points
by
rwestergren
11y ago
|
9 comments
56.
▲
by
rwestergren
11y ago
Perhaps someone wasn't following the bug bounty rules?
57.
▲
by
rwestergren
11y ago
You were spamming and rightly banned for it. https://www.reddit.com/wiki/reddiquette
58.
▲
Verizon Mobile APIs Part 2: Multiple vulnerabilities exposing customer info
(randywestergren.com)
1 points
by
rwestergren
11y ago
|
0 comments
59.
▲
Attacking Z-Way Controlled Home Automation Devices
(randywestergren.com)
2 points
by
rwestergren
11y ago
|
1 comments
60.
▲
Wawa Rewards Gift Card Takeover Vulnerability
(randywestergren.com)
1 points
by
rwestergren
11y ago
|
0 comments
More ›