Jump to content
akkiliON

[SCD + URL Redirection] [*].yahoo.com

Recommended Posts

  • Active Members
Posted

Salut tuturor,

Am creat acest topic s? v? spun c? am g?sit trei vulnerabilit??i în ni?te subdomenii, care apar?in de Yahoo. Am g?sit 1x URL Redirection ?i 2x Source Code Disclosure. Mai unpic am s? primesc ?i recompensele.

Azi diminea?? am primit acest mesaj la fiecare bug raportat.

Thank you for reporting a security vulnerability to Yahoo, we truly appreciate your commitment, energy, and dedication to make Yahoo a safer place on the web.

As you may know we are in the process of updating our vulnerability reporting program, as detailed here <http://yahoodevelopers.tumblr.com/post/62953984019/so-im-the-guy-who-sent-the-t-shirt-out-as-a-thank-you>.

If you have not already done so, please provide your name and best email address and we will get back to you shortly regarding a reward.

Regards,

Yahoo Security Contact

Nu are rost s? mai postez vreo poz? pt c? ?ti?i cum arat? source code disclosure ?i url redirection.

  • Active Members
Posted
felicitari ! , pentru xss stored cat ai primt?

Nimic. E reparat ?i f?r? nici un r?spuns. Mi-a zis un prieten c? cineva de pe twitter a g?sit 2 xss-uri în Yahoo! Mail. Se poate din cauza asta. Le-am trimis un mesaj s? v?d ce spun.

  • Active Members
Posted

Înc? un xss la care am primit r?spuns !

Hello,

Thanks for sending this vulnerability our way. We were able to verify it and have the appropriate team working on it.

As you may know we are in the process of updating our vulnerability reporting program, as detailed here:

<http://yahoodevelopers.tumblr.com/post/62953984019/so-im-the-guy-who-sent-the-t-shirt-out-as-a-thank-you>.

Please hang tight to hear back from us regarding the next steps.

Posted (edited)

Care este timpul de raspuns ? Am si eu 3 trimise de luni (14.10) si inca nu am un raspuns. MS

L.E: pana la modificarea adusa acestui program, primeam un raspuns in maxim 24h.

Edited by nacks
  • Active Members
Posted (edited)
Care este timpul de raspuns ? Am si eu 3 trimise de luni (14.10) si inca nu am un raspuns. MS

L.E: pana la modificarea adusa acestui program, primeam un raspuns in maxim 24h.

Depinde. Eu din 12 oct am trimis un xss si astazi am primit un mesaj.

Edited by akkiliON
Posted

Am primit si eu raspuns:

Thank you for reporting a security vulnerability to Yahoo, we truly appreciate your commitment, energy, and dedication to make Yahoo a safer place on the web. As you may know we are in the process of updating our vulnerability reporting program, as detailed here <http://yahoodevelopers.tumblr.com/post/62953984019/so-im-the-guy-who-sent-the-t-shirt-out-as-a-thank-you>. If you have not already done so, please provide your name and best email address and we will get back to you shortly regarding a reward.

Regards,
Yahoo Security Contact

  • Active Members
Posted

Update:

Yahoo! has awarded you a $394 bounty for 6594****:

Open redirect uk.local.yahoo.com

Yahoo! has awarded you a $250 bounty for 660****:

Self inflicted XSS on tw.myblog.yahoo.com

  • Upvote 1

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...