Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Free Bugs Campaign

Avatar for 8ayac 8ayac
March 11, 2019

Free Bugs Campaign

Burp Suite Japan LT Carnivalの登壇資料

Avatar for 8ayac

8ayac

March 11, 2019
Tweet

More Decks by 8ayac

Other Decks in Technology

Transcript

  1. : -> @8ayac (Twitter/HackerOne/Flickr) 2 PSIRT (’18/04~) MBSD Cybersecurity Challenges

    (’17/’18) GitLab Bug Bounty Program - Hall of Fame 7 (2018) 45 BugHunt / (←New!) CWE CWE-79 / CWE-400 Follow @8ayac 1
  2. + DEMO + α Stored XSS(1) - $0 - $0

    Stored XSS(2) - $0 Free Bugs Campaign Follow @8ayac 16
  3. Title: Issue Stored XSS Issue Type: XSS(CWE-79) Severity: High(7~8.9) Affected

    Versions: 11.3.x < 11.3.1 11.2.x < 11.2.4 11.1.x < 11.1.7 Report: https://hackerone.com/reports/384255 Follow @8ayac 20
  4. Title: Issue Type: Information Exposure Through Browser Caching(CWE-525) Severity: Medium

    Affected Versions: 11.4.x < 11.4.3 11.3.x < 11.3.8 11.2.x < 11.2.7 Report: https://hackerone.com/reports/407763 Follow @8ayac 29
  5. Title: Stored XSS Issue Type: XSS(CWE-79) Severity: High Affected Versions:

    11.4.x < 11.4.3 11.3.x < 11.3.8 11.2.x < 11.2.7 Report: https://hackerone.com/reports/409380 Follow @8ayac 44
  6. @zseano : Are you submitting bugs for free when others

    are being paid?... Follow @8ayac 59