Saturday 23 July 2016

Hacker finds security hole in Vine that allowed him to download the entire source code

Twitter, like many other companies, has a bug bounty program that pays fairly well and quickly for anyone who reports a vulnerability. Bug bounties are a concept that involve companies paying hackers to find vulnerabilities in the company’s systems. It achieves two things: it allows for a crowd-sourced security analysis, and also deters hackers from maliciously exploiting the vulnerability.

Encouraged by Twitter’s bug bounty program, a researcher going by the handle “avicoder” has beenlooking into Twitter- and Vine-related vulnerabilities for quite some time. What he found earlier most recently, however, is probably more than he bargained for. Using censys.io, avicoder found a publicly accessible subdomain that appeared to have been configured for Docker. For the full article click here 



from hacker samurai http://ift.tt/2a46YAb
via IFTTT

No comments:

Post a Comment