Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Free Bugs Campaign

8ayac
March 11, 2019

Free Bugs Campaign

Burp Suite Japan LT Carnivalの登壇資料

8ayac

March 11, 2019
Tweet

More Decks by 8ayac

Other Decks in Technology

Transcript

  1. : -> @8ayac (Twitter/HackerOne/Flickr) 2 PSIRT (’18/04~) MBSD Cybersecurity Challenges

    (’17/’18) GitLab Bug Bounty Program - Hall of Fame 7 (2018) 45 BugHunt / (←New!) CWE CWE-79 / CWE-400 Follow @8ayac 1
  2. + DEMO + α Stored XSS(1) - $0 - $0

    Stored XSS(2) - $0 Free Bugs Campaign Follow @8ayac 16
  3. Title: Issue Stored XSS Issue Type: XSS(CWE-79) Severity: High(7~8.9) Affected

    Versions: 11.3.x < 11.3.1 11.2.x < 11.2.4 11.1.x < 11.1.7 Report: https://hackerone.com/reports/384255 Follow @8ayac 20
  4. Title: Issue Type: Information Exposure Through Browser Caching(CWE-525) Severity: Medium

    Affected Versions: 11.4.x < 11.4.3 11.3.x < 11.3.8 11.2.x < 11.2.7 Report: https://hackerone.com/reports/407763 Follow @8ayac 29
  5. Title: Stored XSS Issue Type: XSS(CWE-79) Severity: High Affected Versions:

    11.4.x < 11.4.3 11.3.x < 11.3.8 11.2.x < 11.2.7 Report: https://hackerone.com/reports/409380 Follow @8ayac 44
  6. @zseano : Are you submitting bugs for free when others

    are being paid?... Follow @8ayac 59