create account

RE: [Security/Bug Report] Steemit.com is vulnerable to "Slow Post" and "Slowloris" DOS attacks by lukestokes

View this thread on: hive.blogpeakd.comecency.com

Viewing a response to: @spaced/security-bug-report-steemit-com-is-vulnerable-to-slow-post-and-slowloris-dos-attacks

· @lukestokes ·
Thank you for your efforts, @spaced. Maybe the Steemit team could create a https://bugcrowd.com/ account and handle bugs that way? I'd imagine there's an incentive for them to _not_ publicly want their issues aired out, especially if they could be exploited before being patched. Responsible disclosure and all that. I think visibility on this stuff is incredibly important, I'm just not sure this is the best medium for it regarding everyone's best interests.

Also... boobs and cat pictures. People like silly things and audience for a deep dive technical analysis of security vulnerabilities is small (though I enjoyed this).

> Anything that is too dangerous to share publicly will be disclosed privately to the developers directly.

Thanks for that. The world needs more white-hat security professionals like you. I hope your efforts are properly rewarded.
👍  
properties (23)
authorlukestokes
permlinkre-spaced-security-bug-report-steemit-com-is-vulnerable-to-slow-post-and-slowloris-dos-attacks-20160713t163829200z
categorysecurity
json_metadata{"tags":["security"],"links":["https://bugcrowd.com/"]}
created2016-07-13 16:38:30
last_update2016-07-13 16:38:30
depth1
children0
last_payout2016-08-17 21:31:45
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length861
author_reputation554,601,966,217,919
root_title"[Security/Bug Report] Steemit.com is vulnerable to "Slow Post" and "Slowloris" DOS attacks"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id97,201
net_rshares1,513,067,682
author_curate_reward""
vote details (1)