Showing posts with label Bug Bounty Program. Show all posts
Showing posts with label Bug Bounty Program. Show all posts
Tuesday, April 9, 2013
0
Tuesday, April 9, 2013
Nauman Ashraf
-->
POC Screen Shot:
The Security researcher told The Hackers Post that he reported XSS flaw to Microsoft. He got immediate response with appreciation and vulnerability fixed by them.
XSS (Cross Site Scripting)
[#] - Vendor homepage:
http://www.microsoft.com
[#] - Tested on:
Windows 7 64 bit Firefox browser (but should have worked on other OS and browsers (not sure about IE))
[#] - Vulnerability Status:
FIXED [Critical]
[#] - Found By:
Omary Lhoussine
[#] - Vulnerable link (POC):
The XSS vulnerability can cause multiple damages like embedding javascript, VBScript, ActiveX, HTML, or Flash into a vulnerable dynamic page and to affect the user. A basic guide on the topic of Cross Site Scripting (XSS) can be found here.
The Security Researcher also listed on Microsoft Security Acknowledgement page .
Read More..
XSS Vulnerability on Microsoft Security Response Center, found by Moroccan Researcher
A young Moroccan Security Researcher discovers XSS (Cross Site Scripting) flaw on Microsoft Security Response Center (MSRC) website. Vulnerability immediately fixed by Microsoft Security Team after reporting.
POC Screen Shot:
The Security researcher told The Hackers Post that he reported XSS flaw to Microsoft. He got immediate response with appreciation and vulnerability fixed by them.
Microsoft Security Team immediately patched the XSS flaw which was reported by me. I have reported many others vulnerabilities which are not fixed yet![#] - Vulnerability Type:
XSS (Cross Site Scripting)
[#] - Vendor homepage:
http://www.microsoft.com
[#] - Tested on:
Windows 7 64 bit Firefox browser (but should have worked on other OS and browsers (not sure about IE))
[#] - Vulnerability Status:
FIXED [Critical]
[#] - Found By:
Omary Lhoussine
[#] - Vulnerable link (POC):
http://www.microsoft.com/security/msrc/report/disclosure.aspx#" onload="alert(document.cookie)See Also: Amazon vulnerable to XSS flaw found by Security Researcher
The XSS vulnerability can cause multiple damages like embedding javascript, VBScript, ActiveX, HTML, or Flash into a vulnerable dynamic page and to affect the user. A basic guide on the topic of Cross Site Scripting (XSS) can be found here.
The Security Researcher also listed on Microsoft Security Acknowledgement page .
Saturday, March 16, 2013
0
Saturday, March 16, 2013
Nauman Ashraf
Read More..
Pakistani Security Researcher gets 500$ Reward for Facebook Bug Bounty Program
A Pakistani Security Researcher, Former Black Hat - Haider Mehmood Qureshi, gets 500$ reward from Facebook under Facebook Bug Bounty Program for reporting HTML Injection flaw on Facebook mobile site.
Below are the details of Bug provide by the Researcher to The Hackers Post.
[#] - Vulnerability Title:
HTML Injection
[#] - Vendor homepage:
http://m.facebook.com
[#] - Remote/Local:
Remote
[#] - Tested on:
Windows 7 64 bit Firefox browser (but should have worked on other OS and browsers (not sure about IE))
[#] - Vulnerability Submitted:
12/1/2013
[#] - Vulnerability Status:
FIXED
[#] - Vulnerable Parameter:
https://m.facebook.com/survey.php?incorrect_brand¶ms=
Facebook mobile provides a survey to evaluate the mobile user experience as they surf facebook mobile site. Here is the survery link: https://m.facebook.com/survey.php .
While entering the mobile phone brands , it provides a list of brands in case you didn't type the correct brand.
The list that was provided contained their HTML code inside the parameter
https://m.facebook.com/survey.php?incorrect_brand¶ms=[HTML code of Brands and Radio Buttons]
Remote User can add any brand Name and Radio buttons, hence allowing Remote HTML injection. It was as simple as it sounds. This could also result in adding junk entries into to database hence causing spam, because remote user can add entries and submit.
Below is the screenshot of a portion of exact POC Researcher submitted to Facebook:
Below my the first reply from Facebook and they acknowledged the issue
below is their reply after 2 months when they fixed the issue

below is their email regarding my eligibility of bug bounty and details.
There is increase rise in black hats changing their dimensions towards bug reporting rather than exploiting them. Yesterday, we reported the youngest security researcher found XSS flaw on Amazon Site.
About Security Researcher Haider:
Haider Mehmood Qureshi is a BS Computer Sciences Student from Comsats Intitute of information technology Islamabad, He do freelancing as Penetration Tester, Started learning pentesting/hacking in 2009. Initially, he was into defacing websites just for fun, later realized to make Pentesting/Security auditing as my career. You can contact security researcher here.
Below are the details of Bug provide by the Researcher to The Hackers Post.
[#] - Vulnerability Title:
HTML Injection
[#] - Vendor homepage:
http://m.facebook.com
[#] - Remote/Local:
Remote
[#] - Tested on:
Windows 7 64 bit Firefox browser (but should have worked on other OS and browsers (not sure about IE))
[#] - Vulnerability Submitted:
12/1/2013
[#] - Vulnerability Status:
FIXED
[#] - Vulnerable Parameter:
https://m.facebook.com/survey.php?incorrect_brand¶ms=
Facebook mobile provides a survey to evaluate the mobile user experience as they surf facebook mobile site. Here is the survery link: https://m.facebook.com/survey.php .
While entering the mobile phone brands , it provides a list of brands in case you didn't type the correct brand.
The list that was provided contained their HTML code inside the parameter
https://m.facebook.com/survey.php?incorrect_brand¶ms=[HTML code of Brands and Radio Buttons]
Remote User can add any brand Name and Radio buttons, hence allowing Remote HTML injection. It was as simple as it sounds. This could also result in adding junk entries into to database hence causing spam, because remote user can add entries and submit.
Below is the screenshot of a portion of exact POC Researcher submitted to Facebook:
Below my the first reply from Facebook and they acknowledged the issue
below is their reply after 2 months when they fixed the issue

below is their email regarding my eligibility of bug bounty and details.
There is increase rise in black hats changing their dimensions towards bug reporting rather than exploiting them. Yesterday, we reported the youngest security researcher found XSS flaw on Amazon Site.
About Security Researcher Haider:
Haider Mehmood Qureshi is a BS Computer Sciences Student from Comsats Intitute of information technology Islamabad, He do freelancing as Penetration Tester, Started learning pentesting/hacking in 2009. Initially, he was into defacing websites just for fun, later realized to make Pentesting/Security auditing as my career. You can contact security researcher here.
Friday, January 25, 2013
0
Friday, January 25, 2013
Nauman Ashraf
Avast announced the launch of the company's new security bug bounty program, according to a recent post on avast. Avast will be offering bounties to security researchers for disclosing vulnerabilities in its products.
Bug Submissions are not accepted by avast from the following countries: Iran, Syria, Cuba, North Korea and Sudan.
Email address to report Bug:
Read More..
Avast announces Bug Bounty Program
Avast announced the launch of the company's new security bug bounty program, according to a recent post on avast. Avast will be offering bounties to security researchers for disclosing vulnerabilities in its products.
We at Avast take this very seriously. We know that being a market leader (Avast has more users than any other AV company in the world), we’re a very attractive target for the attackers. So, here’s our call to action: let’s unite and find and fix those bugs before the bad guys do!The rewards start at $200 (150 EUR), but they can be as high as $5,000 (3,750 EUR) for remote code execution vulnerabilities. In order to be eligible for the bounty, the bug must be original and previously unreported.
Bug Submissions are not accepted by avast from the following countries: Iran, Syria, Cuba, North Korea and Sudan.
Email address to report Bug:
bugs@avast.comSo start bug hunting...Good Luck !!
Subscribe to:
Posts
(
Atom
)





