Bug Bounty

Tue
29
Sep

Flowdock API - Four Vulnerabilities Patched in a Batch

Flowdock API - Four Vulnerabilities Patched in a Batch

Flowdock is a Chat & inbox for teams.. One place to talk and stay up-to-date. Flowdock is a team collaboration app for desktop, mobile & web. Keeping Flowdock`s environment and customer data safe and secure is a top priority for us. The Evolution Security | Vulnerability Laboratory researcher team found four vulnerabilities in the Flowdock API and reported the issues to the vendor.

The Flowdock security team responded as soon as possible and worked with the researchers on the different patches. All vulnerabilities have been fixed within the shortest time and it was a responsible behavior by Flowdock Sec Team. After creating  all patches the researchers were rewarded with Bug Bounties - in form of real $ cash - for every single issue. No T-Shirts included (thank you).

Fri
11
Sep

Paypal Inc - Medium Severity Open Redirect Web Vulnerability fixed!

Paypal | Open Redirect Web Vulnerability

Paypal Inc - Medium Severity Open Redirect Web Vulnerability fixed!

Security researcher Ayoub Ait Elmokhtar found an Open Redirect Web Vulnerability (EIBBP-32252) in the official PayPal web application. The vulnerability has been accepted by Paypal and the researcher was rewarded with 250 US$. The researcher started the research by the use of different versions of known redirect issues like for instance:

https://www.google.com/search?btnI&q=allinurl:evolution-sec.com

It will redirect you to evolution-sec.com since this is an open redirect vulnerability in Google, since Google allow open redirect and didn't consider it in scope of Bug Bounty.

Pages

Subscribe to RSS - Bug Bounty