
<?xml version="1.0"
@spacedhttp://.li\"alert(a.source)</SCRIPTCRIPT>a=/XSS/ alert(a.source)</SCRIPT>>alert(a.source)</SCRIPT>
Resource Credits
Available
Used
Location
<?xml version="1.0" ?>
Created
2016-07-11 17:40
RSS Feed
[AMA I hunt BUGS, and collect BUG BOUNTYs] Hello Everyone, please read this, it took two years to find two of these, and I'm back and finding the SECOND CRITICAL XSS bug in steemit.com. Please READ & afterwards vote up for attention
SECURE DISCLOSURE With issues like these, it can be hard to get the attention of those who need to know, I have sent emails to Ned, but I'm not in the inner circle. I mostly just hang out on Steemit and
[Bug Report] I found an XSS attack in the new profile settings but because Steemit community is so awesome and a self healing organism I'm going to report it privately because the community rewards white hats
I have reported several bugs, most don't receive much but when an article telling hackers to report bugs instead of using the hacks got 3,000 USD in rewards while my reporting of dangerous bugs was getting
[Bug Report] I found an XSS attack in the new profile settings but because Steemit community is so awesome and a self healing organism I'm going to report it privately because the community rewards white hats
I have reported several bugs, most don't receive much but when an article telling hackers to report bugs instead of using the hacks got 3,000 USD in rewards while my reporting of dangerous bugs was getting
\\\\\\\\\art\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\art\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
Why did a post telling people to report bugs make 3,000 USD in upvotes and my actual post about a legitimate security issue that the developers directly thanked me get less than 100 USD?
I wrote these two posts before the hack: [Security/Bug Report] Steemit.com is vulnerable to "Slow Post" and "Slowloris" DOS attacks Steemit.com Administrators: You should not allow
![[AMA I hunt BUGS, and collect BUG BOUNTYs] Hello Everyone, please read this, it took two years to find two of these, and I'm back and finding the SECOND CRITICAL XSS bug in steemit.com. Please READ & afterwards vote up for attention](/assets/noimage.png)