<?xml version="1.0"?>
<rss version="2.0"><channel><title>Bug Bounty Latest Topics</title><link>https://rstforums.com/forum/forum/46-bug-bounty/</link><description>Bug Bounty Latest Topics</description><language>en</language><item><title>rstforums vulnerabil iarasi</title><link>https://rstforums.com/forum/topic/123938-rstforums-vulnerabil-iarasi/</link><description><![CDATA[<p>
	<a href="https://rstforums.com/?%7C%7B___/%7B../" rel="external nofollow">https://rstforums.com/?|{___/{../</a><br />
	<a href="https://rstforums.com/?.%7B%7D__/../+1-2" rel="external nofollow">https://rstforums.com/?.{}__/../+1-2</a>
</p>

<p>
	 
</p>

<p>
	vedeti mai baieti ca trebuie schimbata tema. va zic ceva dar sa nu va suparati. din informatiile mele is niste probleme cu db. cineva a vandut baza de date. nu stiu daca nu e proces pe rol sa va inchida. aveti multi dusmani. sifonari diicot mai oameni.
</p>
]]></description><guid isPermaLink="false">123938</guid><pubDate>Fri, 26 Sep 2025 03:08:48 +0000</pubDate></item><item><title><![CDATA[rstforums path traversal & remote command execution]]></title><link>https://rstforums.com/forum/topic/123933-rstforums-path-traversal-remote-command-execution/</link><description><![CDATA[<p>
	<a href="https://rstforums.com/forum/?%7C%7B___/%7B../" rel="">https://rstforums.com/forum/?|{___/{../</a>
</p>

<p>
	 
</p>

<p>
	nu stiu ce e cu tema, puteti sa ma injurati dar eu va zic sincer ca cineva a vandut baza de date din informatiile mele. nu e bine.
</p>
]]></description><guid isPermaLink="false">123933</guid><pubDate>Thu, 25 Sep 2025 06:55:17 +0000</pubDate></item><item><title>arhi - zoso si cyberfolks pwned</title><link>https://rstforums.com/forum/topic/123724-arhi-zoso-si-cyberfolks-pwned/</link><description><![CDATA[<p>
	<a href="https://arhiblog.ro/a-murit-ion-iliescu/?ID?+1+2___/%7C../%7C" rel="external nofollow">https://arhiblog.ro/a-murit-ion-iliescu/?ID?+1+2___/|../|</a>
</p>

<p>
	 
</p>

<p>
	<a href="https://zoso.ro/best-posts/?ID___/../" rel="external nofollow">https://zoso.ro/best-posts/?ID___/../</a>
</p>

<p>
	<br />
	<a href="https://cyberfolks.ro/hosting-pentru-e-commerce/?ID___/%7C../%7C" rel="external nofollow">https://cyberfolks.ro/hosting-pentru-e-commerce/?ID___/|../|</a>
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">123724</guid><pubDate>Tue, 12 Aug 2025 16:46:40 +0000</pubDate></item><item><title>ro [dot] stripchat [.] com</title><link>https://rstforums.com/forum/topic/123221-ro-dot-stripchat-com/</link><description><![CDATA[<p>
	<a href="https://ro.stripchat.com/%7C/+-*___/" rel="external nofollow">https://ro.stripchat.com/|/+-*___/</a>
</p>

<p>
	 
</p>

<p>
	Nu filtreaza, e 404 e ok, e path traversal ca mai mult nu pot scoate.
</p>

<p>
	 
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">123221</guid><pubDate>Wed, 02 Jul 2025 11:03:59 +0000</pubDate></item><item><title>Am intrat pe site-ul festivalului... si site-ul m-a invitat &#xEE;n back(END)stage</title><link>https://rstforums.com/forum/topic/121225-am-intrat-pe-site-ul-festivalului-si-site-ul-m-a-invitat-%C3%AEn-backendstage/</link><description><![CDATA[<p>
	Le-am trimis un heads-up organizatorilor—sper să repare bug-urile înainte să devină cap de afiș <span>. </span>
</p>

<p>
	 
</p>

<p>
	<span>Note: Ei au spus ca au rezolvat...eu zic ca nu <span><img alt=":))" data-emoticon="" src="https://rstforums.com/forum/uploads/emoticons/default_21.gif" title=":))" />, din acest motiv o sa cenzurez anumite lucruri.</span></span>
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	<img alt="Wc78DfD.jpeg" class="ipsImage" data-ratio="31.88" height="132" width="414" src="https://i.imgur.com/Wc78DfD.jpeg" />
</p>

<p>
	 
</p>

<p>
	<img alt="kfwJ67m.jpeg" class="ipsImage" data-ratio="99.35" height="153" width="154" src="https://i.imgur.com/kfwJ67m.jpeg" />
</p>

<p>
	 
</p>

<p>
	<img alt="Xjfihp4.jpeg" class="ipsImage" data-ratio="40.29" height="110" width="273" src="https://i.imgur.com/Xjfihp4.jpeg" />
</p>
]]></description><guid isPermaLink="false">121225</guid><pubDate>Thu, 03 Apr 2025 14:14:20 +0000</pubDate></item><item><title><![CDATA[kavspersky path traversal & remote command execution]]></title><link>https://rstforums.com/forum/topic/121219-kavspersky-path-traversal-remote-command-execution/</link><description><![CDATA[<p>
	Au fost postate 4 bug-uri in Kavspersky.Rezolvat!
</p>
]]></description><guid isPermaLink="false">121219</guid><pubDate>Wed, 02 Apr 2025 11:44:13 +0000</pubDate></item><item><title><![CDATA[yahoo mail path transveral & rce]]></title><link>https://rstforums.com/forum/topic/120917-yahoo-mail-path-transveral-rce/</link><description><![CDATA[<p>
	<a href="https://mail.yahoo.com/d/folders/1?reason=../___/+1+2" rel="external nofollow">https://mail.yahoo.com/d/folders/1?reason=../___/+1+2</a>
</p>

<p>
	 
</p>

<p>
	donte for more !
</p>

<p>
	 
</p>

<p>
	15xxNpfQEEa7G8ypzFVS681xGkKzJRmaJE
</p>
]]></description><guid isPermaLink="false">120917</guid><pubDate>Mon, 10 Feb 2025 10:59:51 +0000</pubDate></item><item><title>https://dnsc.ro</title><link>https://rstforums.com/forum/topic/120888-httpsdnscro/</link><description><![CDATA[<p>
	<a href="https://dnsc.ro/contact?=___/%7C../++" rel="external nofollow">https://dnsc.ro/contact?=___/|../++</a>
</p>

<p>
	 
</p>

<p>
	for red bull
</p>

<p>
	 
</p>

<p>
	15xxNpfQEEa7G8ypzFVS681xGkKzJRmaJE
</p>

<p>
	 
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">120888</guid><pubDate>Tue, 04 Feb 2025 08:13:29 +0000</pubDate></item><item><title>netbet [dot] ro</title><link>https://rstforums.com/forum/topic/120881-netbet-dot-ro/</link><description><![CDATA[<p>
	<a href="https://ajutor.netbet.ro/hc/ro-ro/?=)%7B../%5D%7B___/" rel="external nofollow">https://ajutor.netbet.ro/hc/ro-ro/?=){../]{___/</a>
</p>

<p>
	 
</p>

<p>
	eu ce sa le fac daca au interzis siteurile straine de betting.e monopol..
</p>

<p>
	 
</p>

<p>
	donate for hell <span style="background-color:#181a20;color:#eaecef;font-size:14px;">15xxNpfQEEa7G8ypzFVS681xGkKzJRmaJE</span>
</p>
]]></description><guid isPermaLink="false">120881</guid><pubDate>Sun, 02 Feb 2025 03:14:06 +0000</pubDate></item><item><title>sie . ro</title><link>https://rstforums.com/forum/topic/120880-sie-ro/</link><description><![CDATA[<p>
	deja filtreaza...
</p>

<p>
	 
</p>

<p>
	donate for beer.
</p>

<p>
	 
</p>

<p>
	<span style="background-color:#ffffff;color:#1d2228;font-size:13px;text-align:left;">3GGpsTMZ9j2Ua8L5Y3TZESeHagR3RoNSCA</span>
</p>
]]></description><guid isPermaLink="false">120880</guid><pubDate>Sun, 02 Feb 2025 03:05:58 +0000</pubDate></item><item><title>https://edition.cnn.com</title><link>https://rstforums.com/forum/topic/120879-httpseditioncnncom/</link><description><![CDATA[<p>
	<a href="https://edition.cnn.com/?./../___/1+2+3" rel="external nofollow">https://edition.cnn.com/?./../___/1+2+3</a>
</p>

<p>
	 
</p>

<p>
	donate for red bull here
</p>

<p>
	 
</p>

<p>
	<span style="background-color:#181a20;color:#eaecef;font-size:14px;">15xxNpfQEEa7G8ypzFVS681xGkKzJRmaJE</span>
</p>
]]></description><guid isPermaLink="false">120879</guid><pubDate>Sun, 02 Feb 2025 02:56:16 +0000</pubDate></item><item><title>betano pwned</title><link>https://rstforums.com/forum/topic/120877-betano-pwned/</link><description><![CDATA[<p>
	<a href="https://ro.betano.com/?.+-0../___/" rel="external nofollow">https://ro.betano.com/?.+-0../___/</a>
</p>

<p>
	<a href="https://ro.betano.com/?=___/%7C../++" rel="external nofollow">https://ro.betano.com/?=___/|../++</a>
</p>

<p>
	 
</p>

<p>
	ce sa fac daca intorc pariurile si te fac de bani.nu is pe hackerone ori bugcrowd sa descriu ca e 3 dimineata, dar las un link de donate daca mai vreti si alte bug-uri, in alte siteuri.
</p>

<p>
	 
</p>

<p>
	btc
</p>

<p>
	 
</p>

<p>
	<span style="background-color:#181a20;color:#eaecef;font-size:14px;">15xxNpfQEEa7G8ypzFVS681xGkKzJRmaJE</span>
</p>
]]></description><guid isPermaLink="false">120877</guid><pubDate>Sun, 02 Feb 2025 01:47:57 +0000</pubDate></item><item><title>niste jegosi de la bugcrowd</title><link>https://rstforums.com/forum/topic/120838-niste-jegosi-de-la-bugcrowd/</link><description><![CDATA[<p>
	mi au respins prima data 3 bug-uri ca is false pozitive si apoi le au patchuit.
</p>

<p>
	 
</p>

<p>
	link scos banuti buni !
</p>

<p>
	 
</p>

<p>
	asta e cadou.eu nu mai am sqlmap, metaspolit.dar e sqli, e lfi, e shell.
</p>
]]></description><guid isPermaLink="false">120838</guid><pubDate>Wed, 29 Jan 2025 12:57:40 +0000</pubDate></item><item><title>MSRC - 2023 Most Valuable Security Researchers</title><link>https://rstforums.com/forum/topic/118799-msrc-2023-most-valuable-security-researchers/</link><description><![CDATA[<div class="ipsEmbeddedOther" contenteditable="false">
	<iframe allowfullscreen="" data-controller="core.front.core.autosizeiframe" data-embedid="embed21137827" src="https://rstforums.com/forum/index.php?app=core&amp;module=system&amp;controller=embed&amp;url=https://twitter.com/msftsecresponse/status/1688964130395557888" style="height:525px;"></iframe>
</div>

<p>
	 
</p>

<p>
	Blog: <a href="https://msrc.microsoft.com/blog/2023/08/congratulations-to-the-msrc-2023-most-valuable-security-researchers/" rel="external nofollow">https://msrc.microsoft.com/blog/2023/08/congratulations-to-the-msrc-2023-most-valuable-security-researchers/</a>
</p>

<p>
	 
</p>

<blockquote class="ipsQuote" data-ipsquote="">
	<div class="ipsQuote_citation">
		Quote
	</div>

	<div class="ipsQuote_contents">
		<p>
			 
		</p>

		<p>
			Our 2023 Top 100 MVRs will receive an MSRC swag box and digital badges to share their accomplishments on social media and professional portfolios. Researchers will be receiving an email from <a href="mailto:msrcmvr@microsoft.com" rel="">msrcmvr@microsoft.com</a> in the coming month to claim their swag and badges.
		</p>

		<p>
			 
		</p>
	</div>
</blockquote>

<p>
	 
</p>

<p>
	 
</p>

<p>
	Leaderboard (2023 MVR): <a href="https://msrc.microsoft.com/leaderboard" rel="external nofollow">https://msrc.microsoft.com/leaderboard</a>
</p>

<p>
	 
</p>

<p>
	Mai sunt doua persoane pe lista si sunt membrii RST: <a contenteditable="false" data-ipshover="" data-ipshover-target="https://rstforums.com/forum/profile/985-zatarra/?do=hovercard" data-mentionid="985" href="https://rstforums.com/forum/profile/985-zatarra/" rel="">@Zatarra</a> @adiivascu.
</p>

<p>
	 
</p>

<p>
	V-am salutat:
</p>

<p>
	 
</p>

<p>
	<img alt="nelson-mondialu-mormant.jpg" class="ipsImage" data-ratio="75.08" height="750" width="1000" src="https://eclujeanul.ro/wp-content/uploads/2014/04/nelson-mondialu-mormant.jpg" />
</p>

<p>
	 
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">118799</guid><pubDate>Tue, 08 Aug 2023 20:09:20 +0000</pubDate></item><item><title>SNSC si contractori individuali / Bug Bounty pe infrastructura Romania?</title><link>https://rstforums.com/forum/topic/118733-snsc-si-contractori-individuali-bug-bounty-pe-infrastructura-romania/</link><description><![CDATA[<p>
	Fiecare initiativa are ca punct de prezentare un site wordpress care ramane neupdatat ani de zile. (fiipregatit.ro, politialocala*x*.ro, universitatii, etc)
</p>

<p>
	 
</p>

<p>
	Potrivit legii, exista undeva, cumva, vreo metoda tip bug bounty? 
</p>

<p>
	 
</p>

<p>
	Honestly m-am saturat sa vad "operation romania" cu RCE pe wordpress 1.0 ./exploit si un deface sau un stored xss, sunt atat de low hanging fruits care pot fi remediate atat de usor
</p>

<p>
	 
</p>

<p>
	ex: in prezent daca faci un request la transport public [oras romania] in api cu un startdate din anul 0001, dai shutdown la api timp de ~1h (ce opreste toate serviciile si 3rd party app din functionare din orasu respectiv) <img alt="=))" data-emoticon="" src="https://rstforums.com/forum/uploads/emoticons/default_24.gif" title="=))" /> nu mai zic nimic
</p>

<p>
	<br />
	cum ne putem implica ca cetateni in asa ceva, si also sa primim ceva la schimb (bani/diplome/etc)
</p>

<p>
	 
</p>

<p>
	ps: Sugestii tip "sparge si da-le mail" nu prea functioneaza pentru ca nu stii peste ce dai, si chiar si sa nu dai peste nimic, egal de intenti nu ai autorizatie 
</p>

<p>
	 
</p>

<p>
	pana si <a href="https://hackerone.com/superbet?type=team" rel="external nofollow">SuperBet </a>are program de bug bounty <span><span><span class="ipsEmoji">?</span> </span></span> 
</p>

<p>
	 
</p>

<p>
	Backgroundu meu sa nu fiu prea specific
</p>

<p>
	Certificari Securitate<br />
	Facultate pe domeniu<br />
	Experienta de munca ce m-ar considera medium in securitate partea Red Team
</p>
]]></description><guid isPermaLink="false">118733</guid><pubDate>Tue, 01 Aug 2023 13:50:26 +0000</pubDate></item><item><title>XSS Reflected - Zendesk</title><link>https://rstforums.com/forum/topic/116487-xss-reflected-zendesk/</link><description><![CDATA[<div class="ipsEmbeddedOther" contenteditable="false">
	<iframe allowfullscreen="" data-controller="core.front.core.autosizeiframe" data-embedid="embed2759797488" src="https://rstforums.com/forum/index.php?app=core&amp;module=system&amp;controller=embed&amp;url=https://twitter.com/akkiliON_/status/1641098564788006912?ref_src=twsrc%255Etfw" style="height:582px;"></iframe>
</div>

<p>
	 
</p>

<p>
	 
</p>

<p>
	Un XSS reflected care a afectat multe companii. Cei de la Zendesk au program bug bounty, dar din pacate am luat duplicat pe aceasta problema. 
</p>
]]></description><guid isPermaLink="false">116487</guid><pubDate>Wed, 29 Mar 2023 15:39:10 +0000</pubDate></item><item><title>XSS Reflected - www.apple.com</title><link>https://rstforums.com/forum/topic/116348-xss-reflected-wwwapplecom/</link><description><![CDATA[<p>
	Un XSS Reflected in www.apple.com. Raportul a fost acceptat. Nu sunt sigur daca o sa primesc vreo recompensa, dar am sa va zic.
</p>

<p>
	 
</p>

<p>
	<span style="background-color:#2e3035;color:#ffffff;font-size:16px;"><img alt="izpDk0W.jpg" class="ipsImage" data-ratio="75.08" height="695" width="1000" src="https://i.imgur.com/izpDk0W.jpg" /></span>
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	 
</p>

<h2>
	Issues eligible for public acknowledgment.
</h2>

<div>
	<div>
		<p>
			We review all issues reported to us, and all legitimate services issues are eligible for public <a href="https://support.apple.com/en-us/HT201536" rel="external nofollow">acknowledgement</a>. While we request that you report all issues, the following issues are eligible for bounty reward payments only if they’re evaluated as novel or high impact based on Apple’s discretion.
		</p>

		<p>
			 
		</p>

		<ul>
			<li>
				Open Redirects
			</li>
			<li>
				<u><em>Reflected or Self XSS</em></u>
			</li>
			<li>
				Bugs requiting exceeding unlikely user interaction
			</li>
			<li>
				Cross-site request forgery vulnerabilities where the only impact is logout
			</li>
			<li>
				Banner Grabbing or Service Versions without a vulnerability or PoC
			</li>
			<li>
				Rate Limiting unless credentials are able to be guessed
			</li>
			<li>
				External and Public Credential Dumps
			</li>
			<li>
				Denial of Service vulnerabilities
			</li>
			<li>
				Username enumeration unless some personal identifiable information is disclosed like email or phone number
			</li>
			<li>
				Report from automated tools or scanners where the vulnerability is not proven
			</li>
			<li>
				Expired Certificates
			</li>
			<li>
				DMARC/SPF Misconfiguration concerns
			</li>
			<li>
				Social engineering
			</li>
			<li>
				Properties that are not owned or operated by Apple
			</li>
		</ul>

		<p>
			 
		</p>

		<p>
			Link: <a href="https://security.apple.com/bounty/categories/" rel="external nofollow">https://security.apple.com/bounty/categories/</a>
		</p>
	</div>
</div>
]]></description><guid isPermaLink="false">116348</guid><pubDate>Tue, 31 Jan 2023 20:27:40 +0000</pubDate></item><item><title>XSS Stored - Microsoft Teams</title><link>https://rstforums.com/forum/topic/116345-xss-stored-microsoft-teams/</link><description><![CDATA[<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="https://rstforums.com/forum/uploads/monthly_2023_01/image.png.2621ba034b84ad09993dbfe518be2e4a.png" data-fileid="324" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="324" data-ratio="50.00" width="1000" alt="image.thumb.png.d78cbab4aa8a752306d3a719f893eebd.png" src="https://rstforums.com/forum/uploads/monthly_2023_01/image.thumb.png.d78cbab4aa8a752306d3a719f893eebd.png" /></a>
</p>

<p>
	 
</p>

<p>
	Raportat. Astept sa vedem ce si cum.
</p>
]]></description><guid isPermaLink="false">116345</guid><pubDate>Tue, 31 Jan 2023 09:40:07 +0000</pubDate></item><item><title>Lista site-urilor care au un program Bug Bounty</title><link>https://rstforums.com/forum/topic/63550-lista-site-urilor-care-au-un-program-bug-bounty/</link><description><![CDATA[<p>Vom mentine aici o lista cu site-urile care au un program bug bounty.</p><p><strong>Google</strong></p><p></p><div></div><pre class="ipsCode">http://www.google.com/about/appsecurity/reward-program/</pre><p></p><p><strong>Facebook</strong></p><p></p><div></div><pre class="ipsCode">https://www.facebook.com/whitehat/bounty</pre><p></p><p><strong>Mozilla</strong></p><p></p><div></div><pre class="ipsCode">http://www.mozilla.org/security/bug-bounty.html</pre><p></p><p><strong>Paypal</strong></p><p></p><div></div><pre class="ipsCode">https://www.paypal.com/us/webapps/mpp/security/reporting-security-issues</pre><p></p><p><strong>Secunia</strong></p><p></p><div></div><pre class="ipsCode">http://secunia.com/community/research/svcrp/</pre><p></p><p><strong>Etsy</strong></p><p></p><div></div><pre class="ipsCode">http://codeascraft.etsy.com/2012/09/11/announcing-the-etsy-security-bug-bounty-program/</pre><p></p><p><strong>Barracuda</strong></p><p></p><div></div><pre class="ipsCode">http://www.barracudalabs.com/bugbounty/</pre><p></p><p>----------------------------------------------------------------------------------------------</p><p>Site-uri care vor mentiona persoanele care le raporteaza vulnerabilitati:</p><p><strong>Adobe</strong></p><p></p><div></div><pre class="ipsCode">http://www.adobe.com/support/security/alertus.html</pre><p></p><p><strong>Twitter</strong></p><p></p><div></div><pre class="ipsCode">https://twitter.com/about/security</pre><p></p><p><strong>EBay</strong></p><p></p><div></div><pre class="ipsCode">http://pages.ebay.com/securitycenter/ResearchersAcknowledgement.html</pre><p></p><p><strong>Microsoft</strong></p><p></p><div></div><pre class="ipsCode">http://technet.microsoft.com/en-us/security/ff852094.aspx</pre><p></p><p></p><p><strong>Apple</strong></p><p></p><div></div><pre class="ipsCode">http://support.apple.com/kb/HT1318</pre><p></p><p><strong>Dropbox</strong></p><p></p><div></div><pre class="ipsCode">https://www.dropbox.com/security</pre><p></p><p><strong>Reddit</strong></p><p></p><div></div><pre class="ipsCode">http://code.reddit.com/wiki/help/whitehat</pre><p></p><p><strong>Github</strong></p><p></p><div></div><pre class="ipsCode">https://help.github.com/articles/responsible-disclosure-of-security-vulnerabilities</pre><p></p><p><strong>Ifixit</strong></p><p></p><div></div><pre class="ipsCode">http://www.ifixit.com/Info/responsible_disclosure</pre><p></p><p><strong>37 Signals</strong></p><p></p><div></div><pre class="ipsCode">http://37signals.com/security-response</pre><p></p><p><strong>Twilio</strong></p><p></p><div></div><pre class="ipsCode">http://www.twilio.com/blog/2012/03/reporting-security-vulnerabilities.html</pre><p></p><p><strong>Constant Contact</strong></p><p></p><div></div><pre class="ipsCode">http://www.constantcontact.com/about-constant-contact/security/report-vulnerability.jsp</pre><p></p><p><strong>Engine Yard</strong></p><p></p><div></div><pre class="ipsCode">http://www.engineyard.com/legal/responsible-disclosure-policy</pre><p></p><p><strong>Lastpass</strong></p><p></p><div></div><pre class="ipsCode">https://lastpass.com/support_security.php</pre><p></p><p><strong>RedHat</strong></p><p></p><div></div><pre class="ipsCode">https://access.redhat.com/knowledge/articles/66234</pre><p></p><p><strong>Acquia</strong></p><p></p><div></div><pre class="ipsCode">https://www.acquia.com/how-report-security-issue</pre><p></p><p><strong>Zynga</strong></p><p></p><div></div><pre class="ipsCode">http://company.zynga.com/security/whitehats</pre><p></p><p><strong>Owncloud</strong></p><p></p><div></div><pre class="ipsCode">http://owncloud.org/security/policy</pre><p></p><p><strong>Tuenti</strong></p><p></p><div></div><pre class="ipsCode">http://corporate.tuenti.com/en/dev/hall-of-fame</pre><p></p><p><strong>Soundcloud</strong></p><p></p><div></div><pre class="ipsCode">http://help.soundcloud.com/customer/portal/articles/439715-responsible-disclosure</pre><p></p><p><strong>Nokia Siemens Networks</strong></p><p></p><div></div><pre class="ipsCode">http://www.nokiasiemensnetworks.com/about-us/responsible-disclosure</pre><p></p><p><strong>Yandex Bug Bounty</strong></p><p></p><div></div><pre class="ipsCode">http://company.yandex.com/security/hall-of-fame.xml </pre><p></p><p>Lista originala: <a href="http://www.ehackingnews.com/2012/12/list-of-bug-bounty-program-for.html" rel="external nofollow">List of Bug Bounty program for PenTesters and Ethical Hackers - E Hacker News</a></p><p>Lista este in curs de actualizare. Daca aveti ceva de completat, postati in acest topic si vom actualiza si aici.</p>
]]></description><guid isPermaLink="false">63550</guid><pubDate>Sat, 13 Apr 2013 07:28:09 +0000</pubDate></item><item><title>XSS DOM Based - www.intel.com</title><link>https://rstforums.com/forum/topic/116214-xss-dom-based-wwwintelcom/</link><description><![CDATA[<p>
	Un XSS Dom Based in <a href="http://www.intel.com" rel="external nofollow">www.intel.com</a>. Din pacate, nu ofera bani pentru aplicatiile web. 
</p>

<p>
	 
</p>

<p>
	<span style="background-color:#2e3035;color:#ffffff;font-size:16px;"><img alt="lvfpfW9.png" class="ipsImage" data-ratio="75.08" height="286" width="1000" src="https://imgur.com/lvfpfW9.png" /></span>
</p>

<p>
	 
</p>

<p>
	<a href="https://app.intigriti.com/programs/intel/intel/detail" rel="external nofollow">https://app.intigriti.com/programs/intel/intel/detail</a>
</p>

<p>
	 
</p>

<blockquote class="ipsQuote" data-ipsquote="">
	<div class="ipsQuote_citation">
		Quote
	</div>

	<div class="ipsQuote_contents">
		<p>
			<strong style="background-color:#ffffff;border:0px;color:#575865;font-size:14px;padding:0px;vertical-align:baseline;">Intel's Web Infrastructure, i.e.<code style="border:0px;font-size:12px;padding:0.2em 0.4em;vertical-align:baseline;">*.intel.com</code></strong><br style="background-color:#ffffff;color:#575865;font-size:14px;" />
			<span style="background-color:#ffffff;color:#575865;font-size:14px;">Intel’s web infrastructure, i.e., website domains owned and/or operated by Intel, fall </span><strong style="background-color:#ffffff;border:0px;color:#575865;font-size:14px;padding:0px;vertical-align:baseline;">Out of Scope</strong><span style="background-color:#ffffff;color:#575865;font-size:14px;">. These reports are not eligible for rewards of any kind.</span><br style="background-color:#ffffff;color:#575865;font-size:14px;" />
			<span style="background-color:#ffffff;color:#575865;font-size:14px;">Please send security vulnerability reports against intel.com and/or related web presence to </span><a href="mailto:external.security.research@intel.com" rel="" style="background-color:#ffffff;border:0px;font-size:14px;padding:0px;vertical-align:baseline;">external.security.research@intel.com</a>
		</p>
	</div>
</blockquote>

<p>
	 
</p>

<p>
	Vulnerabilitatea a fost raportata.
</p>
]]></description><guid isPermaLink="false">116214</guid><pubDate>Tue, 03 Jan 2023 22:17:57 +0000</pubDate></item><item><title><![CDATA[XSS reflected - outlook.[*].com & [*].live.com]]></title><link>https://rstforums.com/forum/topic/115868-xss-reflected-outlookcom-livecom/</link><description><![CDATA[<p>
	Salut. Am gasit doua vulnerabilitati XSS in aplicatiile detinute de cei de la Microsoft. Una este in Outlook, iar a doua intr-o alta aplicatie folosita si cunoscuta de multi... nu pot da detalii momentan deoarece nu a fost rezolvata nici una pana acum... Cel putin, nu am primit duplicat pe rapoartele trimise. <span class="ipsEmoji">?</span>
</p>

<p>
	 
</p>

<p>
	1. XSS reflected (without user interaction) - [*].live.com:
</p>

<p>
	 
</p>

<p>
	<img alt="xss-live.png" class="ipsImage" data-ratio="70.31" height="450" width="640" src="https://i.ibb.co/v3mmRZY/xss-live.png" />
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	2. XSS reflected (user interaction required) - Outlook:
</p>

<p>
	 
</p>

<p>
	<img alt="xss-outlook.png" class="ipsImage" data-ratio="67.81" height="434" width="640" src="https://i.ibb.co/163GR3g/xss-outlook.png" />
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	Am observat ca si domeniile acestea sunt vulnerabile: office365.com si live.com.
</p>
]]></description><guid isPermaLink="false">115868</guid><pubDate>Sat, 01 Oct 2022 19:13:59 +0000</pubDate></item><item><title>XSS Pcfarm.ro</title><link>https://rstforums.com/forum/topic/115869-xss-pcfarmro/</link><description><![CDATA[<p>
	<a href="https://imgur.com/yw1Yi3H" rel="external nofollow">https://imgur.com/yw1Yi3H</a>
</p>

<p>
	 
</p>

<p>
	Raportat. 
</p>
]]></description><guid isPermaLink="false">115869</guid><pubDate>Sun, 02 Oct 2022 16:00:05 +0000</pubDate></item><item><title>Gls.ro IDOR</title><link>https://rstforums.com/forum/topic/115393-glsro-idor/</link><description><![CDATA[<p>
	Daca tot n-au bug bounty, plm have fun <span><img alt=":))" data-emoticon="" src="https://rstforums.com/forum/uploads/emoticons/default_21.gif" title=":))" />.</span>
</p>

<p>
	 
</p>

<p>
	Linkul ar veni ceva gen  "<a href="https://dm.mygls.ro/Account/Login?parcelNumber=11111111111&amp;pin=11af" rel="external nofollow">https://dm.mygls.ro/Account/Login?parcelNumber=11111111111&amp;pin=11af</a>"
</p>

<p>
	 
</p>

<p>
	Daca gasesti valorile potrivite, poti sa intrii in comanda respectiva si sa modifici adresa de livrare + numar de telefon <span><img alt=":))" data-emoticon="" src="https://rstforums.com/forum/uploads/emoticons/default_21.gif" title=":))" /> </span>
</p>

<p>
	 
</p>

<p>
	<span>Enjoy!</span>
</p>
]]></description><guid isPermaLink="false">115393</guid><pubDate>Tue, 08 Mar 2022 18:27:05 +0000</pubDate></item><item><title>XSS Reflected - https://www.xoom.com (PayPal)</title><link>https://rstforums.com/forum/topic/114806-xss-reflected-httpswwwxoomcom-paypal/</link><description><![CDATA[<p>
	O vulnerabilitate pe care am descoperit-o in <a href="https://www.xoom.com/." rel="external nofollow">https://www.xoom.com/</a>. Aplicatia este detinuta de cei de la PayPal. Este o problema mai veche. Recompensa: 5,300$
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	<img alt="E4HCdpoXwAIhNPV?format=jpg&amp;name=large" class="ipsImage" data-ratio="74.90" height="541" width="1000" src="https://pbs.twimg.com/media/E4HCdpoXwAIhNPV?format=jpg&amp;name=large" />
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">114806</guid><pubDate>Thu, 17 Jun 2021 20:22:33 +0000</pubDate></item><item><title>Bug Bounty Resources</title><link>https://rstforums.com/forum/topic/115150-bug-bounty-resources/</link><description><![CDATA[<p>
	Write-ups of All types Bugs<br />
	Bug Bounty Writeups and exploit‘s resource
</p>

<p>
	 
</p>

<p>
	Read More : <a href="https://reconshell.com/bug-bounty-resources/" rel="external nofollow">https://reconshell.com/bug-bounty-resources/</a>
</p>
]]></description><guid isPermaLink="false">115150</guid><pubDate>Sun, 07 Nov 2021 07:32:43 +0000</pubDate></item></channel></rss>
