Disclosure of private programs that have an "external" page on HackerOne

Disclosed: 2016-04-01 08:31:28 By saeedhashem To security
Unknown
Vulnerability Details
Hay again , We know that there are some companies have "external" page on HackerOne : https://hackerone.com/directory?query=type%3Aexternal&sort=name%3Aascending&page=1 Some of those companies are hosting private programs as well , (with the same handles) We can pick up any program from the external programs list , and find out if it hosting a private program or not , by applying this https://hackerone.com/<program_handle>/thanks If it returned 200 OK statue with the thanks page of demo programs with demo thanked researchers , then it's hosting a private program on HackerOne {F79965} . I think it's the same as #116029 minus the activities disclosure part , which obviously pumped up his bounty :D Thanks,
Actions
View on HackerOne
Report Stats
  • Report ID: 124611
  • State: Closed
  • Substate: resolved
  • Upvotes: 4
Share this report