nitter
INTIGRITI
@intigriti
4 Oct 2019
What is the easiest bounty you have earned so far? 💰✅
55
29
119
Mahmoud Gamal
@Zombiehelp54
4 Oct 2019
$10k for an authentication bypass by removing “employee” from the scope parameter in an oauth url which led to access all internal services with a normal user account.
2
2
28
Aaron Parecki
@aaronpk
4 Oct 2019
Replying to
@Zombiehelp54
@intigriti
do you have a link to a summary of this that's public? I would love to include this in an upcoming talk.
Oct 4, 2019 · 3:09 PM UTC
1
Mahmoud Gamal
@Zombiehelp54
4 Oct 2019
Replying to
@aaronpk
@intigriti
Unfortunately, it’s not a public program.