Think this is puny — I found the ability to reveal emails in npmjs.org but as it hadn't been included in the new GitHub/Microsoft bug bounty scope yet, I was given a t-shirt and $1000.
I think this is puny: I was able to take over accounts on a cybersecurity platform just by knowing their account email and was only paid $200
I think this is puny; I can take down almost any site on the internet just by knowing the DNS name, and in exchange all I get is threats of criminal prosecution under anti-DDoS laws
Do you mind sharing which platform?
I was able to run JavaScript inside an email in the GMail app on Android (it required the user tap within the email body). I only got a Nexus 7 tablet.
I've discovered I can run JavaScript in the browser and I've got a job :(
I'm so sorry my friend!
in an old company of mine they started an intranet but if you opened it as http instead of https you'd see raw codes inclusive sql passwords and everything ; i reported to them, to which they replied "yeah just open it with https like everyone else"