Jump to content

nacks

Active Members
  • Posts

    415
  • Joined

  • Last visited

  • Days Won

    2

Posts posted by nacks

  1. Am primit si eu raspuns:

    Thank you for reporting a security vulnerability to Yahoo, we truly appreciate your commitment, energy, and dedication to make Yahoo a safer place on the web. As you may know we are in the process of updating our vulnerability reporting program, as detailed here <http://yahoodevelopers.tumblr.com/post/62953984019/so-im-the-guy-who-sent-the-t-shirt-out-as-a-thank-you>. If you have not already done so, please provide your name and best email address and we will get back to you shortly regarding a reward.

    Regards,
    Yahoo Security Contact

  2. Eu astept de mai bine de o luna sa mi trimita "some new gear" asa cum mi au spus, iar acum imi trimit ceva de genul:

    *****,
    Please allow some more time for your package to reach you.

    Regards,
    Yahoo! Security Contact

    ... deci nici macar de atat nu sunt in stare, dat fiind ca am raportat 3 XSS si inca o eroare intr o aplicatie ... :|

  3. Target: YAHOO

    URL: ***.yahoo.com

    Tested on: Win7 – Mozilla Firefox 23.0

    PoC:

    2ywa.jpg

    Raportat ...

    L.E: Persistent + o eroare ciudata

    ","emails":["******@yahoo.com","******@gmail.com"],"tz":"Europe/Istanbul"}; }(this));

  4. Thanks for passing on this information. We take genuine security threats seriously at Cisco, and have ensured your report has reached the right place for review and inspection.

    Thanks,

    Jin Yang

    Information Security Investigator

    Computer Security Incident Response Team

    Asta am primit pana acum ...

    MS

  5. ^ printre care te numeri si tu. Pun pariu ca nu esti roman si folosesti google translate, altfel nu-mi pot explica exprimarea ta.

    On topic: @naks s-a schimbat ceva pe la yahoo si te rasplatesc in functie de numarul vulnerabilitatilor raportate sau a ramas drept rasplata acel tricou ?

    S au mai schimbat lucrurile ... te rasplatesc in functie de nivelul vulnerabilitatii sau de numarul vulnerabilitatilor trimise.

    Intr un mail primit acum ceva timp se observa acest aspect:

    I want to locate your past reports so I can determine what gift to send to you.

    Regards,
    Yahoo! Security Contact

  6. Daca nu esti inscris in "Developer API program" care te costa ~ 100$ , raportul tau nu o sa il valideze si nici nu o sa primesti cine stie ce feedback .

    Eu am gasit in fiecare domeniu a lor , erau peste 8 XSS-uri si nu am vazut nimic pana in ziua de azi .

    Oricum, Felicitari!

    OffTopic:

    Nu are rost sa cauti in AT&T si Yandex , iti spun din propria experienta.

    Da, stiu ca trebuie sa platesti pt a te inscrie in acel program ... MS de sfat :)

×
×
  • Create New...