bagder,
@bagder@mastodon.social avatar
  1. do not assume that URLs will be treated the same cross user-agents.

  2. do not assume that IPv4-mapped IPv6-addresses can be written in octal.

Another day. Another security report against we could close.

https://hackerone.com/reports/2493548

vastodon,

@bagder nicely handled! Thanks for taking the time to respond to these reports! Its widely underestimated how much time, knowledge and mental effort it takes to deal with these reports on a regular basis.

bagder,
@bagder@mastodon.social avatar

@vastodon thank you. Yes, it does take a significant amount of time and effort ... but luckily, sometimes we can get more value out of single issues by sharing the lessons with a wider audience after the fact.

luc122c,

@bagder 9.8 critical? 😬

bagder,
@bagder@mastodon.social avatar

@luc122c I suppose everyone is allowed an opinion...

mondanzo,
@mondanzo@uwuwatch.club avatar

@bagder it dreads me that some responses seem chatgptfied.

bagder,
@bagder@mastodon.social avatar

@mondanzo me too. It seems more common now for real humans to get chatgpt help phrasing and writing vulnerability reports.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • mdbf
  • GTA5RPClips
  • megavids
  • tacticalgear
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • ethstaker
  • anitta
  • Leos
  • cisconetworking
  • provamag3
  • JUstTest
  • lostlight
  • All magazines