u/Fickle-Champion-2530

Got my second bounty

Got my second bounty

Got my second bounty 1000 usdc. I was hunting on a crypto wallet android App on a selfhosted program. they had an constant called pat with an encrypted value. So i looked for some encryption/decryption methods inside the App and found the and found the decryption class with its hardcoded aes Key and iv. With this I could decrypt the Constant pat value and it was a Github Pat Token With admin Access to all repos of the Company. they fixed it within 10 Hours (reported on friday) and paid me on Monday afternoon. Great Experience

Sorry for the Bad English I am still learning English for Better Communication.

u/Fickle-Champion-2530 — 12 hours ago

Localhost tls private key

Hello Community,

during an analysis of an android App I Discovered it is leaking a tls cert and private Key for localhost.

My question is is there a common abuse Way for it?

i have found a bunch of tls/mtls private keys where the impact was clear.

But this was my first find for local host.

what would You do in such case?

Anyone want to work together on this and teach me a bit? possible bounty will be split 50/50

Thank for your support.

And for my personal interest was this post understandable? I try to avoid ai as much as possible and try to improve my english skills

reddit.com
u/Fickle-Champion-2530 — 3 months ago