Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 6 days ago

The year's 6th day just started and we just clocked in our 8th hackerone report on #curl for the year.

This doesn't work.

3
  • Copy link
  • Flag this post
  • Block
mormund
@mormund@mastodon.social replied  ·  activity timestamp 6 days ago

@bagder Would it be an option to add a small submission fee? That is of course unfair to researchers from developing countries. But $5 should dissuade the AI slop at least a little, I'd imagine.

Not sure if there was already a discussion in another thread about what could be done. Apologies if I have missed that.

Either way this current asymmetry of effort to report vs. effort to check is not sustainable. Thanks for putting up with it so far.

  • Copy link
  • Flag this comment
  • Block
Stefan Eissing
@icing@chaos.social replied  ·  activity timestamp 6 days ago

@bagder I made cron jobs for submitting HackerOne reports on CRLF injections, HTTP headers added by the user and the use of file:// urls to access local data accessible to the user already but with curl instead of notepad.

We could bundle these with the curl release tar ball for further reach. People seem to want those.💁🏻‍♂️

  • Copy link
  • Flag this comment
  • Block
Olivia Vespera
@OliviaVespera@spacey.space replied  ·  activity timestamp 6 days ago

@bagder are these bogus claims?

1
  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp 6 days ago

@OliviaVespera yes, or well, not actual vulnerabilities at least.

  • Copy link
  • Flag this comment
  • Block
Log in

Gnar 🔥 social

This is a Bonfire Federated social instance for those that enjoy gnarly adventures. Whether it's shredding mountains or slaying guitars, from action sports to art.

Gnar 🔥 social: About · Code of conduct · Privacy · Users · Instances
Gnar;🔥 social · 1.0.0-rc.3.6 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login