Active Members akkiliON Posted September 4, 2013 Active Members Report Posted September 4, 2013 # Exploit: *.mozilla.org - Cross-Site-Scripting Reflected# Author: akkiliON# URL Link: https://mozilla.org# PoC: Reported 1 Quote
Active Members akkiliON Posted September 4, 2013 Author Active Members Report Posted September 4, 2013 Da, platesc bine + tricou din câte am v?zut dau. Quote
kalash1337 Posted September 4, 2013 Report Posted September 4, 2013 Da, platesc bine + tricou din câte am v?zut dau. O intrebare, cati bani ai scos din xss-urile gasite. Scoti de un suc? Oricum, bravo Quote
TheTime Posted September 4, 2013 Report Posted September 4, 2013 Felicitari pentru gaselnita! Din pacate, daca este in support.mozilla.org, nu cred ca o sa primesti nimic. Quote
Active Members akkiliON Posted September 4, 2013 Author Active Members Report Posted September 4, 2013 (edited) Felicitari pentru gaselnita! Din pacate, daca este in support.mozilla.org, nu cred ca o sa primesti nimic.What about sites which are notlisted?If you find an issue with a site which is not "officially" part under the web application bug bounty, we would still like to know. If the bug is extraordinary, we might still consider the bug to be nominated for a bounty. In the past we have paid for interesting bugs which are outside of normalpolicy.Nu se ?tie Edited September 4, 2013 by akkiliON Quote
FarSe Posted September 4, 2013 Report Posted September 4, 2013 Bug Bounty nu erau pentru produsele lor? gen firefox,nu cred ca o sa iti iei $3000 pt un xssOricum bravo , pune ban pe ban si iati ceva frumos Quote
Active Members akkiliON Posted September 4, 2013 Author Active Members Report Posted September 4, 2013 Bug Bounty nu erau pentru produsele lor? gen firefox,nu cred ca o sa iti iei $3000 pt un xssOricum bravo , pune ban pe ban si iati ceva frumosDe la 500$ - 3000$ !Nu am zis c? primesc 3000$ pe un XSS de la ei. Quote
FarSe Posted September 4, 2013 Report Posted September 4, 2013 Ah,era scris mai jos,eu ma uitam la "Client Reward Guidelines", nu la "Web Application and Services Reward Guidelines"Oricum bravo . Quote
dang3r1988 Posted September 4, 2013 Report Posted September 4, 2013 nu multi reusesc sa faca asta bravo;) Quote
Active Members akkiliON Posted October 3, 2013 Author Active Members Report Posted October 3, 2013 No reward for this bug (csrf token) Patched. Quote
daatdraqq Posted October 3, 2013 Report Posted October 3, 2013 No reward for this bug (csrf token) Patched.Pai n-ai cum sa interactionezi cu userul din cate vad .Daca n-ai cum sa interactionezi prin click direct e normal sa nu te premieze . Quote
Active Members akkiliON Posted October 3, 2013 Author Active Members Report Posted October 3, 2013 (edited) Pai n-ai cum sa interactionezi cu userul din cate vad .Daca n-ai cum sa interactionezi prin click direct e normal sa nu te premieze .Dac? nu avea CSRF Token îl faceam în GET Method ?i cred c? nu mai aveam treab?. Asta e. Edited October 3, 2013 by akkiliON Quote
daatdraqq Posted October 3, 2013 Report Posted October 3, 2013 Dac? nu avea CSRF Token îl faceam în GET Method ?i cred c? nu mai aveam treab?. Asta e.Ghinionu' coaie ,vorba unui prieten . Quote
Active Members akkiliON Posted October 3, 2013 Author Active Members Report Posted October 3, 2013 Ghinionu' coaie ,vorba unui prieten .Nu e prima dat? când mi se întâmpl?. Quote