Get a Pentest and security assessment of your IT network.

News

Cut-and-paste goof reveals HackerOne session cookie, and earns bug hunter $20,000

HackerOne has paid out a US $20,000 bounty after a researcher discovered he was able to access some other users bug reports on the website. One of the HackerOnes own staff accidentally disclosed one of their own valid session cookies granting the external bug-hunter access to vulnerability reports related to other HackerOne customers. HackerOne notes that its response to the bug report about its own site might have been faster if it hadnt occurred at the weekend.”]

Source: https://grahamcluley.com/cut-and-paste-goof-reveals-hackerone-session-cookie-and-earns-bug-hunter-20000/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin