Open in app

Sign in

Write

Sign in

Japz Divino
Japz Divino

602 Followers

Home

About

Published in

Pinoy White Hat

·Aug 7

HackerOne redacted usernames disclosure in “Export as .pdf” feature

Severity: Low (3.4) Weakness: Sensitive Information Disclosure Bounty: $500 Hello hunters! I just want to share these new findings on the HackerOne bug bounty platform. First, I just wanna let you know that I disagree with the rated severity being Low here, but I always respect the team’s decision and…

Bug Bounty

4 min read

Redacted usernames disclosure in "Export as .pdf" feature
Redacted usernames disclosure in "Export as .pdf" feature
Bug Bounty

4 min read


Published in

Pinoy White Hat

·Jul 4

Getting email address of any HackerOne user worth $7,500

Severity: High (7.5) Weakness: Sensitive Information Disclosure Bounty: Duplicate (First researcher receives $7,500) Hey hunters, I’m back! Just wanna share my recent finding in HackerOne’s own bug bounty program. This finding is pretty much straight forward :) After submitting a report on HackerOne, I’ve added my brother hackerone.com/r3y to the…

5 min read

Getting email address of any HackerOne user worth $7,500
Getting email address of any HackerOne user worth $7,500

5 min read


Published in

Pinoy White Hat

·Oct 31, 2018

Bypass HackerOne 2FA requirement and reporter blacklist

Severity: Medium (5.0) — High (7.1) Weakness: Improper Authorization Bounty: $10,000 Summary: First, the initial submission got a bounty of $2,500. But while HackerOne was doing their Root Cause Analysis (RCA) of my report submission, they have stumbled upon another vulnerability with High severity. Since my submission gives them a…

Security

4 min read

Bypass HackerOne 2FA requirement and reporter blacklist
Bypass HackerOne 2FA requirement and reporter blacklist
Security

4 min read


Published in

Pinoy White Hat

·Oct 22, 2018

Harvesting all private invites using leave program fast-tracked invitation and security@ email forwarding feature

Severity: Medium (6.1) Weakness: Business Logic Errors (CWE-840) Summary: I have found a way that it is possible to harvest all private HackerOne invitation using the Leave Program feature together with the Security@ email forwarding feature without any user interaction. HackerOne Security@ Email Forwarding Feature First, when the program activated…

Security

3 min read

Harvesting all private invites using leave program fast-tracked invitation and security@ email…
Harvesting all private invites using leave program fast-tracked invitation and security@ email…
Security

3 min read


Published in

Pinoy White Hat

·Oct 17, 2018

Security teams Internal attachments can be exported via “Export as .zip” feature on HackerOne

Hello Internet, this blog is about my findings on hackerone own bug bounty program late 2016, a simple information disclosure which hackerone team decided to reward the highest bounty amount in a single hit/submission so far on their own bug bounty program due it’s business impact. Severity: High (7.5) Weakness: Information…

Security

4 min read

Security

4 min read


Published in

Pinoy White Hat

·Sep 2, 2017

IDOR on HackerOne Hacker Review “What Program Say”

Severity: Low Weakness: Insecure Direct Object Reference Hello everyone, welcome to my first blog, I’m going to share my recent finding on HackerOne’s own bug bounty program. NOTE: There are two precondition to successfully exploit the bug. Attacker must be a team member that can review a hacker (hacker program…

Security

4 min read

IDOR on HackerOne Hacker Review “What Program Say”
IDOR on HackerOne Hacker Review “What Program Say”
Security

4 min read

Japz Divino

Japz Divino

602 Followers

OSCP | Security Consultant | Bug Bounty Hunter

Following
  • InfoSec Write-ups

    InfoSec Write-ups

  • Anangsha Alammyan

    Anangsha Alammyan

  • WAX io

    WAX io

  • Samantha

    Samantha

  • Joshua Regio

    Joshua Regio

See all (132)

Help

Status

About

Careers

Blog

Privacy

Terms

Text to speech

Teams