Bitcoin Forum
August 01, 2025, 11:16:58 PM *
News: Latest Bitcoin Core release: 29.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: bitcointalk vulnerability  (Read 346 times)
k3rnel31 (OP)
Newbie
*
Offline Offline

Activity: 10
Merit: 0


View Profile
May 28, 2019, 01:19:47 AM
 #1

hi , i have discovered some vulnerability in bitcointalk in simple machine code , about emails & usernames , would be any bounty if i show them ?

thanks
TryNinja
Legendary
*
Offline Offline

Activity: 3276
Merit: 8534


♻️ Automatic Exchange


View Profile WWW
May 28, 2019, 01:23:11 AM
 #2

Possibly. It depends on what the vulnerability is and what it does.

Everything you need to know can be found here: Security bounties

░░░░▄▄████████████▄
▄████████████████▀
▄████████████████▀▄█▄
▄██████▀▀░░▄███▀▄████▄
▄██████▀░░░▄███▀▀██████▄
██████▀░░▄████▄░░░▀██████
██████░░▀▀▀▀▄▄▄▄░░██████
██████▄░░░▀████▀░░▄██████
▀██████▄▄███▀░░░▄██████▀
▀████▀▄████░░▄▄███████▀
▀█▀▄████████████████▀
▄████████████████▀
▀████████████▀▀░░░░
 
 CCECASH 
 
    ANN THREAD    
 
      TUTORIAL      
ene1980
Hero Member
*****
Offline Offline

Activity: 2002
Merit: 535


View Profile
May 28, 2019, 05:17:10 AM
Last edit: May 28, 2019, 09:00:48 AM by ene1980
 #3

hi , i have discovered some vulnerability in bitcointalk in simple machine code , about emails & usernames , would be any bounty if i show them ?

thanks
You can contact Theymos regarding that, send him a PM and see what he has to say about it or wait until he responds here and i am certain he will give you the bounty if it is a legit vulnerability.


Still trying to figure the last part of your post @OP. If you meant would you be able to join a bounty after you must have shown your claimed discover. I don't think that's possible you don't have the needed rank or activities to join a bounty yet https://bitcointalk.org/index.php?topic=2818350.0

But after showing it if it's good then you can be awarded merit which you require.

He is not talking about joining any bounty mate, he wants to help the forum out and help with solving the vulnerability and if he does that is he eligible for a bounty if he reveals those vulnerability as he claims.
eternalgloom
Legendary
*
Offline Offline

Activity: 1792
Merit: 1283



View Profile
May 28, 2019, 08:48:52 AM
Last edit: May 28, 2019, 12:57:01 PM by eternalgloom
Merited by dbshck (4), LoyceV (1), TryNinja (1)
 #4

Still trying to figure the last part of your post @OP. If you meant would you be able to join a bounty after you must have shown your claimed discover. I don't think that's possible you don't have the needed rank or activities to join a bounty yet https://bitcointalk.org/index.php?topic=2818350.0

But after showing it if it's good then you can be awarded merit which you require.


I laughed out loud when I read this comment :') Completely wrong context, seems that the word bounty only has one meaning for most people on this forum.

OP, definitely do send a pm to Theymos, if you can. Not sure if he'd read PM's from new members, so I'd make the topic of your PM very clear.
Is this a publicly known bug or is it a zero-day that you've found yourself?

Edit:

- 1 XAU: Find the email address of user DefaultTrust and explain in detail how you did it.

No idea how to find the actual email address though. Then again, if you indeed do have access to emails & usernames, you shouldn't have a problem with that Wink

GreatArkansas
Legendary
*
Offline Offline

Activity: 2758
Merit: 1443



View Profile WWW
May 28, 2019, 10:32:47 AM
 #5

Still trying to figure the last part of your post @OP. If you meant would you be able to join a bounty after you must have shown your claimed discover. I don't think that's possible you don't have the needed rank or activities to join a bounty yet https://bitcointalk.org/index.php?topic=2818350.0

But after showing it if it's good then you can be awarded merit which you require.

I laughed out loud when I read this comment :') Completely wrong context, seems that the word bounty only has one meaning for most people on this forum.
Is that considered as 'off-topic' post?
Can I report that post of Sharon121212 to the moderator?


▄███████████████████▄
████████████████████████

██████████▀▀▀▀██████████
███████████████▀▀███████
█████████▄▄███▄▄█████
████████▀▀████▀███████
█████████▄▄██▀██████████
████████████▄███████████
██████████████▄█████████
██████████▀▀███▀▀███████
███████████████████████
█████████▄▄████▄▄████████
▀███████████████████▀
.
 BC.GAME 
███████████████
███████████████
███████████████
███████████████
██████▀░▀██████
████▀░░░░░▀████
███░░░░░░░░░███
███▄░░▄░▄░░▄███
█████▀░░░▀█████

███████████████

███████████████

███████████████

███████████████
███████████████
███████████████
███████████████
███████████████
███░░▀░░░▀░░███
███░░▄▄▄░░▄████
███▄▄█▀░░▄█████
█████▀░░▐██████
█████░░░░██████

███████████████

███████████████

███████████████

███████████████
███████████████
███████████████
███████████████
███████████████
██████▀▀░▀▄░███
████▀░░▄░▄░▀███
███▀░░▀▄▀▄░▄███
███▄░░▀░▀░▄████
███░▀▄░▄▄██████

███████████████

███████████████

███████████████

███████████████

DEPOSIT BONUS
.1000%.
GET FREE
...5 BTC...

REFER & EARN
..$1000 + 15%..
COMMISSION


 Play Now 
hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 4256
Merit: 2792


Join the world-leading crypto sportsbook NOW!


View Profile
May 28, 2019, 11:11:22 AM
Merited by Foxpup (1), eternalgloom (1)
 #6

- 1 XAU: Find the email address of user DefaultTrust and explain in detail how you did it.

.
.Sportsbet.io...F U N  │  F A S T  │  F A I R..
██████
██
██
██
██
██
██
██
██
██
██
██
██████

       ▄███▀   ▄████▀
    ▄███▀   ▄████▀
  ▄███▀   ▄████▀
▄███▀   ▄████▀
▀███▀▀▄████▀
  ▀  ▄████▀
     █████▄▄▄▄▄▄
      ▀█████▀▀
        ▀▀▀
 
█    ██  █   █ ▄▀▀▄  ██
█   ▐▌▐▌ █   █ █ ▄▄ ▐▌▐▌
▀▄▄ █▀▀█ ▀▄▄ █ ▀▄▄▀ █▀▀█
▄▄▄
██████
████████
██████████
████████████
██▀██▀▀▀▀▀▀▀▀▀
░░░░░▄▄█░░░░
░░░░░░░░░░░
▀█▌  ▐██
░░░░▄█▀▀▀░░░░▐███
██▄▄█▄▄█▄▄▄▄▄██▄▄█████
████████████████████████
████████████████████████
▀▀██████████████████▀▀
| 
Official Partner of
LA LIGA
WORLD SNOOKER TOUR
██████
██
██
██
██
██
██
██
██
██
██
██
██████
LoyceV
Legendary
*
Offline Offline

Activity: 3752
Merit: 19429


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
May 28, 2019, 11:57:27 AM
 #7

- 1 XAU: Find the email address of user DefaultTrust and explain in detail how you did it.
So the bounty is 1 ounce of gold, worth $1283.29 and paid as 0.1468BTC?

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
TryNinja
Legendary
*
Offline Offline

Activity: 3276
Merit: 8534


♻️ Automatic Exchange


View Profile WWW
May 28, 2019, 12:02:03 PM
 #8

So the bounty is 1 ounce of gold, worth $1283.29 and paid as 0.1468BTC?
If he "finds the email address of user DefaultTrust and explain in detail how he did it", he gets 1 ounce of gold worth in BTC. That's based on what OP said about his vulnerability: "about emails & usernames";

But, he can get more based on a few factors found in the thread I linked above. Example: Root access from a regular user (8 ounces) related to a security flaw in non-PHP software used by the forum (150%) would give him 150% of 8 oz of gold = 12 oz.

░░░░▄▄████████████▄
▄████████████████▀
▄████████████████▀▄█▄
▄██████▀▀░░▄███▀▄████▄
▄██████▀░░░▄███▀▀██████▄
██████▀░░▄████▄░░░▀██████
██████░░▀▀▀▀▄▄▄▄░░██████
██████▄░░░▀████▀░░▄██████
▀██████▄▄███▀░░░▄██████▀
▀████▀▄████░░▄▄███████▀
▀█▀▄████████████████▀
▄████████████████▀
▀████████████▀▀░░░░
 
 CCECASH 
 
    ANN THREAD    
 
      TUTORIAL      
eternalgloom
Legendary
*
Offline Offline

Activity: 1792
Merit: 1283



View Profile
May 28, 2019, 01:05:46 PM
Merited by GreatArkansas (1)
 #9

Is that considered as 'off-topic' post?
Can I report that post of Sharon121212 to the moderator?

You can report any post you want, it doesn't mean it will be accepted though.

OP, definitely give an update on whether you've received the bounty.
Without disclosing the vulnerability of course Wink

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!