On the morning of the 13th day of the year we have received *checks notes* 13 #curl vulnerability reports on Hackerone this year.
None a confirmed vulnerability.
On the morning of the 13th day of the year we have received *checks notes* 13 #curl vulnerability reports on Hackerone this year.
None a confirmed vulnerability.
Christopher Snowhill
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to daniel:// stenberg:// • • •Ironically, we have also received complaints from people who get annoyed when we disclose so many rubbish reports on Hackerone...
github.com/curl/curl/issues/20โฆ
plz stop publishing NAs / infos to hacktivity on hackerone
teflon-cd (GitHub)daniel:// stenberg://
in reply to daniel:// stenberg:// • • •Stefan Eissing
in reply to daniel:// stenberg:// • • •Very sad indeed.
But we *do* let reports through if the hacker alias is really cool. Which, in these cases, they really werenโt. ๐ฅ๐๐ปโโ๏ธ
Gregory
in reply to daniel:// stenberg:// • • •Mike Anderson
in reply to daniel:// stenberg:// • • •jwz
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to jwz • • •Volker Stolz
in reply to daniel:// stenberg:// • • •Brokar
in reply to daniel:// stenberg:// • • •If they don't check their AI slop before posting, it's up to them to take the (rightful) beating for it.
No mercy.
G Allen
in reply to daniel:// stenberg:// • • •Mike Anderson
in reply to daniel:// stenberg:// • • •Luke Nelson
in reply to daniel:// stenberg:// • • •> it clogs hacktivity for people wanting to read good disclosures
I don't user hackerone but I'd imagine there are filters in the UI to hide these?
daniel:// stenberg://
in reply to Luke Nelson • • •niallor
in reply to daniel:// stenberg:// • • •Carsten
in reply to daniel:// stenberg:// • • •*sigh* that does NOT bode well for the remaining days.
Thanks for enduring this!
Thoralf Will ๐บ๐ฆ๐ฎ๐ฑ๐น๐ผ
in reply to daniel:// stenberg:// • • •If the ratio is too bad, I would consider to simply ignore reports from trash sources. Not worth the effort.