jeffalo @jeffalo

i had a zoom call with people to discuss a major vulnerability i found.

May 6, 2023, 1:57 PM
25

comments

Cool, for which website/app?

ooh i think i might know what it is

i think we’re talking about different things, its when i logged into poprock’s account with a password, even though he had no password assigned.

i cant do it anymore if i try doing it with @owlsss-owlclient

i think you already fixed it

this sounds like a bug with your client rather than the server — as far as i can tell, i haven’t touched auth code in years

huh, maybe, idk

all i know is apparently i logged into an account with a password even though the account had no password assigned, and then you gave me a warning

See more replies

i highly doubt you do lmao

you know jeffalo is serious when he starts using periods in his posts and replies

wait till you see one with capital letters.

You should start documenting your bug bounties. A lot of people do

he might not be able to, because they aren't fixed yet

He's found other ones before

yeah, I know

all my reported bug are documented. i just don’t have permission to publish.

I agree with this, please do, will be an interesting read.