GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Any Hackers in the House? (https://gfy.com/showthread.php?t=1196849)

clickity click 05-12-2016 02:29 PM

Any Hackers in the House?
 
Pornhub are offering $25k if you can find an exploit.

https://hackerone.com/pornhub

CPA-Rush 05-12-2016 02:38 PM

its called pentesting not hacking

clickity click 05-12-2016 02:40 PM

No it's not it's hacking. Pentesting is when you test your pen to see if it still works.

CPA-Rush 05-12-2016 02:43 PM

Quote:

Originally Posted by clickity click (Post 20891051)
No it's not it's hacking. Pentesting is when you test your pen to see if it still works.

penetration testing

clickity click 05-12-2016 02:46 PM

Quote:

Originally Posted by CPA-Rush (Post 20891063)
penetration testing

When you fuck a virgin.

clickity click 05-12-2016 02:47 PM

Anyway CPA-RUSH. What the fuck do you know about it anyway?

T-Rain From Tacoma 05-12-2016 02:52 PM

I hack them all day.. Its a free tube site been going to for years..

plaster 05-12-2016 02:53 PM

Nice.... $25 reward min.

yuu.design 05-12-2016 02:58 PM

intresting!

Colmike9 05-12-2016 03:02 PM

Quote:

Originally Posted by plaster (Post 20891096)
Nice.... $25 reward min.

Looks like it's $50 now :upsidedow

IrwinJones 05-12-2016 03:03 PM

Hacking Beez aint eazy-e

CaptainHowdy 05-12-2016 03:04 PM

Innaresting ...

Bladewire 05-12-2016 03:12 PM

Cool according to the endless terms you have to wait 30 days for a response then 90 days for them to fix it, 120 days (4 months) total. THEY decide if your find is worth $50 or more and you have to trust Pornhub if they tell you it's already been reported to them by someone else :thumbsup

Their terms also state they MAY reward qualifying finds. So even if you're the first to find a huge vulnerability that they fix you are not guaranteed any money at all.

clickity click 05-12-2016 03:22 PM

Quote:

Originally Posted by Bladewire (Post 20891165)
Cool according to the endless terms you have to wait 30 days for a response then 90 days for them to fix it, 120 days (4 months) total. THEY decide if your find is worth $50 or more and you have to trust Pornhub if they tell you it's already been reported to them by someone else :thumbsup

Their terms also state they MAY reward qualifying finds. So even if you're the first to find a huge vulnerability that they fix you are not guaranteed any money at all.

Pretty standard terms really.

Bladewire 05-12-2016 03:29 PM

Quote:

Originally Posted by clickity click (Post 20891183)
Pretty standard terms really.

Nope.

Even Adobe's HackerOne
terms don't have anything close to that kind of wording regarding compensation. They definitely don't say you might find an issue, report it, and not gat paid..

State facts.

CPA-Rush 05-12-2016 03:29 PM

Quote:

Originally Posted by clickity click (Post 20891069)
When you fuck a virgin.

lol what ?

Quote:

Originally Posted by clickity click (Post 20891072)
Anyway CPA-RUSH. What the fuck do you know about it anyway?

<script>alert("XSS")</script>

clickity click 05-12-2016 03:40 PM

Quote:

Originally Posted by CPA-Rush (Post 20891216)
lol what ?



<script>alert("XSS")</script>

Xss is lame.

ladida 05-12-2016 03:48 PM

Quote:

Originally Posted by Bladewire (Post 20891165)
Cool according to the endless terms you have to wait 30 days for a response then 90 days for them to fix it, 120 days (4 months) total. THEY decide if your find is worth $50 or more and you have to trust Pornhub if they tell you it's already been reported to them by someone else :thumbsup

Their terms also state they MAY reward qualifying finds. So even if you're the first to find a huge vulnerability that they fix you are not guaranteed any money at all.

Yea. This is pretty standard in the "hack for ethic" contests like this one why its bullshit to even try to compete.You don't know up front for what vuln or level of compromise you get what compensation. The 25k bounty will not go to anyone even if you breach the server. They also removed all the bullshit vuln's that are usually reported like clickjacking, xss, csrf etc etc, and won't pay for any human error or employee targeting :))))

They'll probably argue 25k would go if you download their database, which is probably few terabytes and how likely is something like that to go unnoticed :) :321GFY
If someone was to found the vuln, you'd sell it better on black market then to them for compensation.

CPA-Rush 05-12-2016 04:03 PM

Quote:

Originally Posted by clickity click (Post 20891249)
Xss is lame.

really ?

Bladewire 05-12-2016 04:07 PM

Quote:

Originally Posted by ladida (Post 20891282)
They'll probably argue 25k would go if you download their database, which is probably few terabytes and how likely is something like that to go unnoticed :) :321GFY
If someone was to found the vuln, you'd sell it better on black market then to them for compensation.

Would be funny if they had a central database that's so old school :1orglaugh

Shitty Yahoo is the ONLY other company in all of HackerOne that is so tacky as to say "Rewards are granted entirely at the discretion of" :1orglaugh:1orglaugh:1orglaugh

clickity click 05-12-2016 04:08 PM

Quote:

Originally Posted by CPA-Rush (Post 20891318)
really ?

Yes......

Bladewire 05-12-2016 04:16 PM

Quote:

Originally Posted by clickity click (Post 20891330)
Yes......

What platform is not vulnerable to XSS?

CPA-Rush 05-12-2016 04:21 PM

Quote:

Originally Posted by Bladewire (Post 20891354)
What platform is not vulnerable to XSS?

:1orglaugh

clickity click 05-12-2016 04:30 PM

Quote:

Originally Posted by Bladewire (Post 20891354)
What platform is not vulnerable to XSS?

Who cares? Just because you can make an alert that makes you l33t.

Bladewire 05-12-2016 04:33 PM

Quote:

Originally Posted by cpa-rush (Post 20891372)
:1orglaugh

?









.

DVTimes 05-12-2016 04:36 PM

Now you can make money watching porn on Pornhub | News | Geek.com

CPA-Rush 05-12-2016 04:37 PM

Quote:

Originally Posted by Bladewire (Post 20891393)
?









.


pfff its mean i agree lol

money biz 05-12-2016 04:53 PM

Quote:

Originally Posted by Bladewire (Post 20891354)
What platform is not vulnerable to XSS?

what ways are even left after reading those terms?

Bladewire 05-12-2016 05:09 PM

Quote:

Originally Posted by DVTimes (Post 20891399)

And get this. :1orglaugh:1orglaugh:1orglaugh

rowan 05-12-2016 05:15 PM

Quote:

Originally Posted by Bladewire (Post 20891165)
Cool according to the endless terms you have to wait 30 days for a response then 90 days for them to fix it, 120 days (4 months) total. THEY decide if your find is worth $50 or more and you have to trust Pornhub if they tell you it's already been reported to them by someone else :thumbsup

Their terms also state they MAY reward qualifying finds. So even if you're the first to find a huge vulnerability that they fix you are not guaranteed any money at all.

Vuln bounties should have some sort of public signature or hash ledger, so that when someone finds one, the finder can prove the time of submission, without releasing the actual details. That way the company cannot weasel out of it by saying that someone else found it first.

Would probably be even better if the proof was stored on a public blockchain, like Bitcoin, so that the company couldn't manipulate it.

There's a startup idea for you. :thumbsup

Phoenix 05-12-2016 05:17 PM

I suspect they will get what they ask for, perhaps not the way they wish though.

Best of luck to the game.

Bladewire 05-12-2016 05:21 PM

Like taking candy from a baby. You can redirect to your own page via a Pornhub post. I do similar on my Tumblrs :1orglaugh:1orglaugh:1orglaugh

Pornhub post offsite redirect example

Wait 8 seconds

Pornhub possibly has a serious Xss gif issue too it seems :helpme

There, where's my money? Oh wait . . .

Bladewire 05-12-2016 05:28 PM

Quote:

Originally Posted by rowan (Post 20891474)
Vuln bounties should have some sort of public signature or hash ledger, so that when someone finds one, the finder can prove the time of submission, without releasing the actual details. That way the company cannot weasel out of it by saying that someone else found it first.

Would probably be even better if the proof was stored on a public blockchain, like Bitcoin, so that the company couldn't manipulate it.

There's a startup idea for you. :thumbsup

Brilliant idea!

With their "hackers bounty" publicity blitz the last few days they'll get a lot of people like me interested, until they read the scammy terms, and I'm not hacker.

With my previous posts "helping" Pornhub you never get public, or private, thanks but see they act on it later, with me at least once that I can remember. There's seemingly more tangible known monetary benefits to not disclosing and using to someone's benefit.

I'm sure my last post will receive the same lack of acknowledgement, let alone gratitude from Pornhub, and that's fine :1orglaugh:1orglaugh:1orglaugh

lezinterracial 05-12-2016 09:02 PM

Quote:

Originally Posted by rowan (Post 20891474)
Vuln bounties should have some sort of public signature or hash ledger, so that when someone finds one, the finder can prove the time of submission, without releasing the actual details. That way the company cannot weasel out of it by saying that someone else found it first.

Would probably be even better if the proof was stored on a public blockchain, like Bitcoin, so that the company couldn't manipulate it.

There's a startup idea for you. :thumbsup

Closest thing I know of is. https://hackerone.com/ and https://www.openbugbounty.org/ At openbounty you can put the details on hold for any site you find a redirect or xss issue with. I put an issue on hold for a month usually. Only a small site paid me. Big sites, never answer.

TheeRoly 05-12-2016 09:54 PM

Another good press release / publicity stunt from the top dawgs in Adult.

JFK 05-13-2016 09:37 AM

Quote:

Originally Posted by Bladewire (Post 20891480)
Like taking candy from a baby. You can redirect to your own page via a Pornhub post. I do similar on my Tumblrs :1orglaugh:1orglaugh:1orglaugh

Pornhub post offsite redirect example

Wait 8 seconds

Pornhub possibly has a serious Xss gif issue too it seems :helpme

There, where's my money? Oh wait . . .

The cheque is in the mail :helpme

Colmike9 05-13-2016 09:42 AM

They said we're not allowed to DDoS or use any kind of bots or scripts and a few other things.. I'm out.

Smut-Talk 07-24-2016 04:35 PM

Quote:

Originally Posted by Bladewire (Post 20891480)
Like taking candy from a baby. You can redirect to your own page via a Pornhub post. I do similar on my Tumblrs :1orglaugh:1orglaugh:1orglaugh

<cant post urls yet... > Pornhub post offsite redirect example

Wait 8 seconds

Pornhub possibly has a serious Xss gif issue too it seems :helpme

There, where's my money? Oh wait . . .

lol

nice one!
no sanitizing on the php call for the title?

Than again lots of sites have 'mistakes' in them.
I can name a few...

Bladewire 07-24-2016 06:20 PM

Quote:

Originally Posted by Smut-Talk (Post 21057268)
lol

nice one!
no sanitizing on the php call for the title?

Than again lots of sites have 'mistakes' in them.
I can name a few...


Just Google XSS Gif Pornhub ;)

Ask Clifford for details it's his work.

Here's his HackerOne profile: https://hackerone.com/trizaeron

Pornhub hasn't paid Clifford according to his profile and he's hacked it since what, March?

Maybe Pornhub doesn't care about people redirecting from their site or don't want to pay the guy what he's worth?

Smut-Talk 07-24-2016 07:51 PM

I just returned from big G was looking for more info.
i can see the kremlin gets lots of traffic from pornhub.. :1orglaugh
Was that you?

but no info on Clifford's hack.


All times are GMT -7. The time now is 10:57 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc