u/Electronic-Cat-2518

2FA bypass via race condition

I found a 2FA bypass where I can send concurrent requests via a single packet attack which bypasses the rate limit for predictable 5 digits, However the program policy has a very tight ceiling of the requests per second making that very time consuming to even record. Is there an alternative to record a POC without breaking the program's policy?

reddit.com
u/Electronic-Cat-2518 — 1 day ago

2FA Enrollment bypass

Found a way to, well, not bypassing the 2FA itself, but bypassing the enrollment step for first time setup after an admin enforces it upon an org, worth reporting?

reddit.com
u/Electronic-Cat-2518 — 1 month ago

Minimum Sunlight UVB for the small species (Russian, Greek and Hermann)

Does 1 or half an hour per week of sunlight suffice for an adult of the aforementioned tortoises, Considering I've heard conflicting opinions, The most common one i've heard is that direct sunlight makes up for the artificial UVB, Which otherwise would require a few hours (With conflict on how many), Don't want to cause bone issues for my tort when I buy it

reddit.com
u/Electronic-Cat-2518 — 2 months ago

Malicious File Upload

yo, found a way to bypass the filter an application enforces for file types through magic bytes, in a chat conversation, the only caveat is that it has to be downloaded and it'll run on the victim's machine then, is that still an issue to report? since the restriction on file types prolly existed for a reason even if that isn't the traditional file upload vuln

reddit.com
u/Electronic-Cat-2518 — 2 months ago

Google Map API Keys

Hi, I'm new to bug bounty. Asking because I don't want to flood the triagers queue with useless things.

I've found a google map api key, I know it's intended for public use, but the one I've found is unrestricted and accepts fake referer headers as well, should I report it?

reddit.com
u/Electronic-Cat-2518 — 2 months ago