Wir möchten uns an dieser Stelle bei wichtigen Helfern bedanken, die uns mit Hinweisen dabei unterstützen, unsere Systeme sicherer zu machen. Unser Dank geht an:
Abdiwahab Ahmed Omar - https://www.facebook.com/0x1h3r/ - Meldung von HTTP header Schwachstellen, Meldung von Information Disclosure Schwachstellen.
Abdlallah Mohammed - https://twitter.com/1bdool492 - Meldung von Server-side request forgery (SSRF) Schwachstellen.
Abdul Azeez Alaseeri - linkedin.com/in/0xx777 - Meldung von Cross-site scripting (XSS) Schwachstellen.
Abdul Haq Khokhar - https://twitter.com/Abdulhaqkhokhar: Meldung von Policy Framework Schwachstellen.
Abdul Mazid - https://x.com/0zidmaz?s=11
Abdul Rehman - @facebook.com/shadowcreator: Meldung von Host Header Schwachstellen.
Abdullah Rahmatullah - Twitter: twitter.com/abd_4fg - Meldung von Cross-site scripting (XSS) Schwachstellen.
Abdulrahman Badawi - https://twitter.com/zikolasec?t=nx1TAITxMlZ6ykoVZFhNNA&s=09 - Meldung von Information Disclosure Schwachstellen.
Abdulrahman Kamel https://www.linkedin.com/in/abdulrahman-kamel/ - Meldung von verschiedenen Cross-site scripting (XSS) Schwachstellen / Meldung von Information Disclosure Schwachstellen und ungesicherter Kommunikation.
Abdulelah BinAqeel - Meldung von reflektiert XSS Schwachstelle.
Abdullah Fares Muhanna - https://www.facebook.com/AbedullahFares - Meldung von Einsatz verwundbarer Software.
Abdulsalam M olamilekan - X: https://x.com/olamdeen
Achmad Marzuki Abdulloh - https://id.linkedin.com/in/achmadabdullah - Meldung von Authentication Bypass.
Adam AL MUSAWE - https://x.com/madocdaloc - Meldung von RCE.
Adam Willard - https://www.linkedin.com/pub/adam-willard/20/575/30b/@aw7684512: Meldung von HTML-Manipulationsschwachstelle.
ADARSH VS https://twitter.com/adarshvs_ - Meldung von Data manipulation Schwachstellen.
Adam Ziaja - http://adamziaja.com: Meldung von SSL Anfälligkeit.
Adegbola Kehinde Peter - Facebook: https://www.facebook.com/Kennygold.404 - Meldung von Disclosure of Secrets, Content Injection Schwachstellen.
Adel Mahmoud - https://www.facebook.com/mohappaaa - Meldung von reflektiert XSS Schwachstelle.
Aditya Dixit - http://fb.com/aditya008 - http://hackthedevil.blogspot.com: Reported DOM based XSS Schwachstellen.
Aditya Jadhav - www.securecyberfuture.com - Meldung von XSS Schwachstellen.
Aditya Singh - https://www.linkedin.com/in/aditya-singh-b78111169/ - Meldung von Account Takeover Schwachstellen.
Aditya Singh - linkedin.com/in/aditya-singh4180/ - Meldung Schwachstelle: Email HTML Injection via name Parameter on Register Page und Sensitive JWT Token Exposure.
Adrian Siefer - Reported "Exposed Brand Dialog API documentation".
Agustín Doménech - https://twitter.com/robotshelld - Meldung von Information Disclosure Schwachstellen.
Ahmad Alassaf - https://www.facebook.com/theviperxx/ - Meldung von Information Disclosure Schwachstellen.
Ahmad Ashraff - @yappare - Path Disclosure.
Ahmad Halabi (Cyber Ironclad) - hackerone.com/ahmd_halabi - Meldung von Information Disclosure Schwachstellen.
Ahmad Karim Dahrouj - https://www.linkedin.com/in/ahmad-karim-dahrouj-51bb49259 - Meldung von Possible DoS Attack Schwachstellen
Ahmad Qaramany (@qaramany0x01) - twitter.com/qaramany0x01 - Meldung von Information Disclosure Schwachstellen.
Ahmed Aaish - https://parallel.solutions - Meldung von JavaServer Faces Schwachstellen.
Ahmed Adel Abdelfattah - https://www.facebook.com/00SystemError00/ - Meldung von XSS Schwachstellen.
Ahmed Alsanosi - facebook.com/01alsanosi - twitter.com/ahmed_alsanosi - Meldung von Unsecured communication Schwachstellen.
Ahmed Ehab - https://twitter.com/HeBo117 - Meldung von Server-side request forgery (SSRF) Schwachstellen.
Ahmed El-Desoky - LinkedIn: www.linkedin.com/in/ahmed-eldesoky-982051227 - Meldung von Cross-site scripting (XSS) Schwachstellen / Meldung von HTTP header Schwachstellen.
Ahmed Elsadat - https://bugcrowd.com/GENERAL-SADAT / https://www.facebook.com/mido.gamal.9674 - Meldung von XSS Schwachstellen.
Ahmed Fahim - Meldung von Information Disclosure Schwachstellen.
Ahmed Ismail linkedin.com/in/ahmed-ismail-38901168 twitter.com/MrOz1l facebook.com/AhmedOzil10 - Subdomain Takeover / Meldung von Broken Access Control Schwachstellen.
Ahmed Jumani - LinkedIn: https://www.linkedin.com/in/ahmedjumani/ Meldung von Exposed Google Maps API Key Schwachstellen.
Ahmed Lotfy (doctor X) - https://x.com/Ahmed846737825 - Meldung von Detailed Server Configuration Page.
Ahmed Max - https://www.facebook.com/profile.php?id=100004971255687; Twitter: @404NotF39672584 - Gefundene content/text injection.
Ahmed Nazmy - Meldung von Remote Code Execution (RCE) Schwachstellen.
Ahmed Qaramany - https://twitter.com/qaramany0x01, https://www.facebook.com/qaramany0x01 - Meldung von Information Disclosure Schwachstellen.
Ahmed Sherif - https://twitter.com/sherif_ninja - Meldung von Server-side request forgery (SSRF) Schwachstellen.
Ahmed Y. Elmogy - Twitter: mogyhacker - Meldung von anti-CSRF/XSS Schwachstellen.
Ahmet Demirci - https://www.facebook.com/ahmet.demirc.17 und https://m-i-a.cf - Meldung von reflektiert XSS Schwachstelle.
Ahmet Gurel - twitter.com/ahmettgurell - Meldung von Cross-site scripting (XSS) Schwachstellen.
Ahmet SUNA - linkedin.com/in/ahmet-suna-ab3ba9116 - Reported Information Disclosure, Host header injection, Cross-site scripting (XSS), Open Redirect and Database backup critical Information Disclosure
Amar Shankar & Piyush Malik: Meldung von XSS Schwachstellen.
Ahmed Salah Abdalhfaz https://twitter.com/Elsfa7110 - Meldung von Information Disclosure Schwachstellen.
Ahmed Sayd - https://www.instagram.com/8l242 - Meldung von Command Injection Schwachstellen.
Ahmed Shawky @lnxg33k: Meldung von SQL Injection.
Ahmed sultan (0x4148) linked in : https://eg.linkedin.com/in/0x4148 - Meldung von SQL Injection.
Ahmed Usama (vulnera) - https://twitter.com/0xvulnera / facebook.com/0xvulnera - Meldung von Cross-site request forgery (CSRF) Schwachstellen.
Ahmet Gurel - twitter.com/ahmettgurell - Reported Cross-site scripting (XSS) / Meldung von SQL injection Schwachstelle.
Ahmet Ümit BAYRAM - www.ahmetumitbayram.com - @ahmetumitbayram - Meldung von reflektiert XSS Schwachstelle.
Ahmed Waheed - @ia7m4d0z: Meldung von XSS Schwachstellen.
Ai Ho - https://twitter.com/j3ssiejjj - Meldung von Information Disclosure Schwachstellen.
Aishwarya KC https://twitter.com/aiswar_ya - Meldung von Subdomain takeover Schwachstellen.
Alwaleed Alfayez - Meldung von SSRF Schwachstellen.
Aly Khaled (0x41ly) - linkedin.com/in/aly-khal3d - hackerone.com/0x41ly?type=user - bugcrowd.com/0x41ly - twitter.com/Aly_Khal3d - Meldung von Possible DoS Attack Schwachstellen, Meldung von Open Redirect Schwachstellen, Cross-site scripting (XSS), Broken Access Control, Open Redirect / Meldung von HTTP header Schwachstellen.
Aman Rawat - https://www.linkedin.com/in/theamanrawat/ - Meldung von Information Disclosure Schwachstellen.
Aman Kumar - https://twitter.com/amykr777 - Meldung von User Enumeration Schwachstellen / Meldung von Information Disclosure Schwachstellen / Meldung von Cross-site scripting (XSS), Open Redirect, Information Disclosure and Path traversal Schwachstellen.
Amaranath Moger - https://www.linkedin.com/in/amaranath-moger/ - Meldung von Broken Access Control Schwachstellen.
Amaranath M - https://www.linkedin.com/in/amaranath-moger/ - Meldung von Broken Access Control Schwachstellen.
Ameya Andhare - https://www.linkedin.com/in/ameya-andhare-ab839b1a5/ / https://twitter.com/AmeyaAndhare - Meldung von Clickjacking Schwachstellen und Information Disclosure.
Amin Achour - www.th-online.ch - Meldung von XSS Schwachstellen.
Aminullah Habibi. - "https://x.com/wdk__23" - Vulnerability: Sensitive Information Exposure.
Amir Habeeb - https://www.linkedin.com/in/amir-habeeb-5a0aba259/ - Reported "Sensitive Information Disclosure".
Amol Bhola - Meldung von Clickjacking Schwachstelle.
Amr Al Hallak - Meldung von Cross-site scripting (XSS) Schwachstellen.
Amr Khaled (0x37U) - https://www.facebook.com/Amr.v7 /
https://twitter.com/0x37U - Meldung von Missing rate limit Schwachstellen.
Amr Salama - LinkedIn: https://www.linkedin.com/in/amrsalama23 / Hinweis auf Broken Authentication and Session Management Schwachstelle.
Anandu Mohan - https://in.linkedin.com/in/anandu-mohan-69b30b13a /Unauthenticated local file read.
Bao Bui (@0xd0ff9) - twitter.com/Jok3rDb - Meldung von Privilege escalation for server/application Schwachstellen / Meldung von Security misconfiguration Schwachstellen.
Bao Chau - https://www.linkedin.com/in/nhubaochau/ - Meldung von Open Redirect Schwachstellen.
Batee5a - hackerone.com/batee5a - Meldung von Local File Inclusion Schwachstellen.
Battal Faik Aktaş - twitter.com/BattalFaikAktas - Meldung von Open Redirect Schwachstellen und diversen Server-side request forgery (SSRF) Schwachstellen / Meldung von Remote Code Execution (RCE) Schwachstellen / Meldung von Information Disclosure und Default login Schwachstellen, Cross-site scripting (XSS).
B. Caller - Meldung von Remote Code Execution (RCE) Schwachstellen.
Ben Chinoy - https://www.linkedin.com/in/benchinoy - Meldung von Broken Access Control Schwachstellen.
Benjamin Kunz Mejri (Evolution Security GmbH - Vulnerability Laboratory) www.vulnerability-lab.com - twitter.com/vuln_lab - Meldung von persistentem XSS Schwachstellen, SQLi, Exec.
Bhanu Teja - twitter.com/bh4nut3j4 - Meldung von Subdomain takeover Schwachstellen / Meldung von Unauthenticated Local File Read Schwachstellen / Meldung von Cross-site scripting (XSS) Schwachstellen / Meldung von User Enumerations Schwachstellen / Meldung von Information Disclosure Schwachstellen.
BHARAT CHOUDHARY - https://twitter.com/iambharat18 - Meldung von Information Disclosure und Open Redirect Schwachstellen.
Bhuwan Bhetwal - https://twitter.com/yamarajislitaf - Meldung von Information Disclosure Schwachstellen.
Bibek Shah - @noobibek - Meldung von verschiedenen Information Disclosure Schwachstellen.
Bilal Teke - https://luckywiki.org - Meldung von XSS Schwachstellen.
Bill Ben Haim - https://www.linkedin.com/in/bill-ben-haim-b6775a48/ - Meldung von default credentials.
Bipul Jaiswal - https://twitter.com/r3curs1v3_pr0xy. - Meldung von Information Disclosure Schwachstellen.
Burak Ünal @_d4rkbrain - twitter.com/_d4rkbrain - Meldung von Information Disclosure Schwachstellen.
Bytes_Knight, https://bugcrowd.com/h/Bytes_Knight, Open redirection, CORS Misconfiguration/ Sensitive Data Hardcoded- Production Admin API Key Exposed.
C
Cale Anderson - Meldung von Broken Authentication Schwachstellen.
Can Karacan - https://www.linkedin.com/in/can-karacan-69ba09b8/- Meldung von Information Disclosure, offenem Mail-Relay und Cross-site scripting (XSS) Schwachstellen.
Cara Sharma - https://www.facebook.com/SharmaCara - https://twitter.com/Sharma_Cara - Meldung von Insecure Cross Domain und CSRF Schwachstellen.
Carl-Theodor Geilhufe – www.carl.geilhufe.de - Meldung von Information Disclosure.
Carlos Cardoso - https://websecauditors.com | facebook.com/cmscardoso – Meldung von fehlkonfigurierten DNS Einträgen.
Cernica Ionut Cosmin: Meldung von Directory Listing Schwachstellen.
Charlie Briggs - @Charlie_N_B: Meldung von XSS Schwachstellen.
Chetan - linkedin.com/in/chetan-00 - Meldung von Information Disclosure Schwachstellen.
Chetan Gulhane - http://varutra.com: Meldung von XSS Schwachstellen.
Chiheb Chebbi - twitter.com/chihebchebbi201 - Meldung von Remote Code Execution (RCE) Schwachstellen / Meldung von Security misconfiguration Schwachstellen.
Chilik Tamir - @_coreDump: Meldung von IOS App Schwachstelle.
Chinmay Barbade - https://www.linkedin.com/in/chinmay-barbade-a36400162/ - Meldung von Broken Access Control Schwachstellen.
Chinmoy Mukherjee chinmoy.info - Meldung von Information Disclosure Schwachstellen.
chippa vijay kumar- https://twitter.com/vijay922 - Meldung von Information Disclosure Schwachstellen.
Chirag Artani - https://twitter.com/chirag99artani https://3rag.com/chirag-artani - Meldung von Open Redirect Schwachstellen / Meldung von HTML/CSS injection Schwachstellen / Meldung von Information Disclosure Schwachstellen / Meldung von Cross-site scripting (XSS) Schwachstellen.
Chirag Goyal - https://www.facebook.com/goyal.chirag23 - Meldung von XSS Schwachstellen.
Chris Green - @chris_t_green - Meldung von XSS-Schwachstellen.
Chris McGowen – http://badcoding.net - @chrismcgowen: Meldung von DOM basierter XSS Schwachstelle.
Deekonda Vinod - twitter.com/vinod_deekonda - Meldung von Information Disclosure Schwachstellen.
Deepak Kumar ( CipherEra) - vedixera.com - Meldung von Information Disclosure Schwachstellen / Meldung von User Enumeration Schwachstellen.
Deepanker Chawla - @deepankerchawla - www.deepanker.in: Meldung von XSS Schwachstellen.
Denis Bazur - argv500@gmail.com: Meldung von XSS Schwachstellen.
Deniz Işık / bursali - Administrator - www.bursali.eu: Meldung von CSS und LFI Schwachstellen in Deutschen Telekom Foren.
Denis Werner – www.nobbd.de, @nobbd - Meldung von SQL Injection Schwachstellen.
Dennis Mwanzia - https://www.linkedin.com/in/dennis-mwanzia-b5b243283/ - Meldung von Information Disclosure Schwachstellen / Meldung von Broken Access Control Schwachstellen.
Devesh bhatt #deveshbhatt11: Meldung von Enumeration in login page.
Dhaffa Nurfahriansyah - https://linkedin.com/in/dhaffanurfahriansyah - Meldung von Information Disclosure Schwachstellen.
Dharmik Fichadiya - https://twitter.com/shelby67051949/ - Meldung von Broken Access Control Schwachstellen.
Dhinu Ramachandran www.linkedin.com/in/dhinu-ramachandran-76683b206 - Meldung von HTTP header Schwachstellen.
Dhrumil Patel - https://dhrumilpatel1209.netlify.app/ - https://www.linkedin.com/in/dhrumilpatel99/ : Meldung von Sensitive Information Disclosure / Improper Access Control.
Dhruvi Pandya - Meldung von Schwachstellen Information Disclosure.
Diego Bernal Adelantado - https://www.linkedin.com/in/diego-bernal-adelantado/ - Meldung von Subdomain takeover Schwachstellen.
Dimpal Jadhav - https://www.linkedin.com/in/dimpal-jadhav-79a4231a3 - Reported "Hardcoded Credentials in Application".
Dmitry Ivanof - Meldung von reflektiert XSS Schwachstelle.
Emad Shanab - Twitter: https://twitter.com/Alra3ees - Meldung von RCE, XSS und Information Disclosure Schwachstellen.
Emad Youssef - twitter.com/Sy3Omda - Meldung von XSS, SSRF, Cross Site Tracing, Server Misconfiguration, Privilege escalation für Server/Applikation, Open Redirect Schwachstellen und mehrere Berichte zu Cross-site scripting (XSS) / Meldung von Information Disclosure Schwachstellen.
Enzo Freitas - https://www.linkedin.com/in/enzo-freitas-095607182/ - Meldung von Server-side request forgery (SSRF) Schwachstellen / Meldung von Cross-site scripting (XSS) Schwachstellen.
Erchiqui Azzeddine - @zertox1: Information Disclosure.
Ereshwari Valmik - https://www.linkedin.com/in/ereshwari-valmik-28b376137 - Meldung von Information Disclosure Schwachstellen / Meldung von Information Disclosure Schwachstellen.
Eric Flokstra - www.linkedin.com/pub/dir/Eric/Flokstra: Meldung von xss Schwachstellen.
Erick Fernando Xavier de Oliveira - https://x.com/erickfernandox - Meldung von Path traversal Schwachstellen.
Erik van Oosbree - www.erikvanoosbree.nl: Meldung von XSS Schwachstellen.
eslamXxX https://www.linkedin.com/in/eslam-sayed-842770160 - Meldung von Open Redirect Schwachstellen.
Eslam Abu Bakr - https://x.com/eabubakr21 - Meldung von verschiedenen Information Disclosure Schwachstellen und Unauthenticated Remote Code Execution / Meldung von Cross-site scripting (XSS) Schwachstellen / Meldung von Information Disclosure Schwachstellen.
Eslam Kamal - https://www.linkedin.com/in/eslam-kamal /https://www.facebook.com/StrikerHacker33- Meldung von Schwachstellen / Meldung von Possible DoS Attack.
Eugen Füchsle - http://fyx.li: Meldung von XSS Schwachstellen.
Eusebiu Blindu - Meldung von XSS Schwachstellen und Nagios Weak Credentials.
Evan Ricafort - www.twitter.com/robinhood0x00: Meldung von XSS Schwachstellen.
F
Fabian Henneke - https://hen.ne.ke / @fhenneke - Meldung von DOM XSS Schwachstellen
Fabian Mucke- https://twitter.com/HerrFabs - Meldung von Subdomain takeover Schwachstellen, Information Disclosure.
Farhin Malek - https://www.linkedin.com/in/farhin-malek28 - Meldung von Clickjacking Schwachstellen.
Fatih GUREL - https://www.linkedin.com/in/fatihgurel/ -Meldung von CORS Schwachstellen, Information Disclosure.
Fatma Elzahraa Mohamed Salam - https://www.linkedin.com/in/fatmaelzahraa-salam-2a38813b3/ - Reported "Nicht authentifizierter Zugriff und Enumeration to Pre-Production Object Storage Bucket"
Fayas S - https://www.linkedin.com/in/fayas--s/ - Meldung von Exposed pprof endpoint leaking VictoriaMetrics Admin Keys.
Felipe Gabriel Renzi - https://www.linkedin.com/in/felipe-gabriel-renzi - Meldung von Information Disclosure und Cross-site scripting (XSS) Schwachstellen.
Filippos Mastrogiannis - @filipposmastro - Meldung von XSS Schwachstelle.
Florian Kunushevci - https://www.facebook.com/florianx00 - Meldung von mehreren XSS Schwachstellen.
Florian Thie - https://florian-thie.de - Meldung einer CSRF-Schwachstelle.
Foysal Ahmed Fahim - hackerone.com/foysal1197 twitter.com/foysal1197 - Meldung von Information Disclosure Schwachstellen, Subdomain takeover, Broken Access Control und HTTP header Schwachstellen / Meldung von Cross-site scripting (XSS) Schwachstellen / Meldung von HTML/CSS injection Schwachstellen / Meldung von Server-side request forgery (SSRF), Meldung von Path traversal Schwachstellen.
Francisco Correa - panchocosil.blogspot.com - @panchocosil: Meldung von sql Schwachstellen.
Francisco Palma - https://twitter.com/1c3t0rm - Meldung von Default login Schwachstellen.
Frank B. Vickers - https://www.linkedin.com/in/frank-vickers-199109a - Meldung einer Webservice-Fehlkonfiguration.
Frans Rosén - Detectify (https://detectify.com): Meldung von XSS Schwachstellen.
Frederik Werner - instagram: werner.frederik - Meldung von Broken Authentication Schwachstellen.
Fredrik Nordberg Almroth: Tilde vulnerability.
G
G Bharath kalyan - https://www.linkedin.com/in/bharath-kalyan-476a651ba - Meldung von Cross-site scripting (XSS) Schwachstellen / Meldung von Information Disclosure Schwachstellen / Meldung von Security misconfiguration Schwachstellen / Meldung von Missing rate limit Schwachstellen.
Gaurang maheta https://www.linkedin.com/in/gaurang-mehta-35515a162 - Meldung von Information Disclosure Schwachstellen, Broken Access Control.
GAURAV R NAIK - https://www.linkedin.com/in/gaurav-r-naik - Meldung von Cross-site scripting (XSS) Schwachstellen.
George Adel Sami Salib https://www.linkedin.com/in/george-adel-5ab77a1b9 - Meldung von Information Disclosure Schwachstellen.
Gia Bui Dai - @yabeow from VNG Corporation - Meldung von Information Disclosure Schwachstellen.
Gineesh George - gineesh-george: Meldung von XSS Schwachstellen.
glatisant - https://twitter.com/glatisantbeast - Meldung von Open Redirect Schwachstellen.
Gokuleshwaran Bharathkumar - https://www.linkedin.com/in/gokuleswaranb-ethacker/ - Reported "Sensitive Data Exposure".
Harikrishnan Dhandapani - https://www.linkedin.com/in/harikrishnan-d/ - Meldung von Broken Access Control Schwachstellen.
Haris Ahmed - https://www.linkedin.com/in/haris-ahmed-ethical-hacker/ / Haris Ahmed (@HarisAhmed95) / Twitter- Meldung von Clickjacking Schwachstellen.
Hari Krishnan - Facebook.com/c.hari1997: Meldung von Clickjacking Schwachstellen.
Harinder Singh (S1N6H) - https://www.linkedin.com/in/lambardar - Meldung von Information Disclosure und Clickjacking Schwachstellen.
Haris Mamoun - Gefundene Remote Code Execution.
Harsh Bhanushali - http://linkedin.com/in/harshbhanushali - Meldung von User Enumeration Schwachstellen.
Harsh maheta - https://www.linkedin.com/in/harsh-maheta-7057542a9?utm_source=share&utm_campaign=share_via&utm_content=profile&utm_medium=android_app - Meldung von Information Disclosure Schwachstellen.
Harsh Parekh https://www.linkedin.com/in/harshparekh11/ - Meldung von Remote Code Execution (RCE) Schwachstellen; Meldung von Information Disclosure Schwachstellen.
Harsha Vardhan Boppana - @hvboppana: Hinweise auf cross site scripting.
Harshil Parikh https://www.linkedin.com/in/harshil-parikh-945bb8201/ - Meldung von Clickjacking Schwachstellen.
Harshit Shukla - http://facebook.com/lords001: Meldung einer HTML Injection Schwachstelle.
Hasan Aliyev - https://www.linkedin.com/in/hasan-aliyev-560723338 - Meldung von Cross-site scripting (XSS) Schwachstellen.
Hasan Al Mahmud - https://www.linkedin.com/in/m4hmud404/ - Meldung von "Unauthenticated firmware distribution leading to supply chain compromise".
Hasan Basri Elisert - https://www.linkedin.com/in/hasanelisert - Meldung von Unsecured communication Schwachstellen.
Hasibul Hasan Rifat - twitter.com/rifatsec - Meldung von Information Disclosure Schwachstellen.
Hasibul Hasan Shawon - saiyan0x01.com - Meldung von Sensitive Data Exposure Schwachstellen.
Iem Prog - www.facebook.com/IEMPROG: Meldung von XSS Schwachstellen.
Ifrah Iman - www.ifrahiman.com / twitter.com/IfrahIman_ - Meldung von XSS Schwachstellen.
Ilamparithi Imayavaramban - https://ilam.page - https://www.linkedin.com/in/ilamparithi-i - Meldung von Business Logic Schwachstellen.
Ilca Lucian: Meldung von XSS Schwachstellen.
İlyas ORAK - tr.linkedin.com/in/ilyasorak - INNOVERABT - (2x) Meldung von reflektiert XSS Schwachstelle.
Ilyes Medjedoub - https://linkedin.in/in/ilyes-medjedoub - Meldung von XSS.
Imen Essoussi: Meldung von SQL Injection Schwachstellen.
Imran Hosssain, X Handel - https://x.com/s41n1k - Meldung von Broken Access Control Schwachstellen.
Indresh Verma - https://twitter.com/Jester0x01 - Meldung von Information Disclosure Schwachstellen.
Infoziant Security - https://in.linkedin.com/company/infoziant-security - Meldung von HTTP header Schwachstellen.
Intrigue team - www.intrigue.io - Meldung von Information Disclosure Schwachstellen.
Ishan Anand - @Zer0-Access: Meldung von XSS Schwachstellen.
ISHAN VYAS https://twitter.com/_snak3_/ - Meldung von Broken Access Control Schwachstellen.
iskhaled nassar twitter.com/knassar702 - Meldung von User Enumeration Schwachstellen, Cross-Site Scripting (XSS), Information Disclosure.
Ismael Hasan - https://www.facebook.com/ismaieil - Meldung von XSS Schwachstellen.
İsmail BÜLBÜL - Uluslararası Siber Güvenlik Federasyonu - Meldung einer Cross-Site-Scripting Schwachstellen.
Ismail Hossain - Twitter: https://twitter.com/cmsajib, Web: https://eesec.org - Meldung einer Text Injection Schwachstelle.
İsmail Taşdelen - https://linkedin.com/in/ismailtasdelen - Meldung von fehlenden Sicherheitsmechanismen, Clickjacking, Information Disclosure und weiteren Schwachstellen, Meldung von Cross-site scripting (XSS) Schwachstellen, Meldung von HTTP header Schwachstellen, Meldung von Security misconfiguration Schwachstellen / Meldung von Server-side request forgery (SSRF) Schwachstellen.
Issam Rabhi (https://sites.google.com/site/issrabhi/): Meldung von XSS Schwachstellen.
J
JAAT Gaurav (@webcipher101) - https://www.linkedin.com/in/gaurav-dalal-0434821b5/ - Meldung von Information Disclosure Schwachstellen.
Jagadeesh - https://www.linkedin.com/in/jagadeesh-jd-79308b93/ - Meldung von clickjacking.
Jai Kumar B linkedin.com/in/jai-kumar-835a54183 - Meldung von Information Disclosure Schwachstellen.
Jake Reynolds | www.depthsecurity.com | https://twitter.com/depthsecurity Meldung von XXE Schwachstellen.
Jamal Eddine El Hadjeui - @jamalc0m: Meldung von Schwachstellen.
Jamal Eddine El Hadjeui – www.paytabs.co: Meldung von Open URL Redirection Schwachstelle.
Jamshid Baghban https://bugforlife.com/ - Meldung von HTTP header Schwachstellen.
Jan Markus Schütz - Meldung von Broken Authentication Schwachstellen.
Jannick Oursin - facebook.com/jannick.oursin - Meldung von Information Disclosure Schwachstellen.
Jan-Peter Rauschning - https://Rauschning.me - Critical Personal Data Information Disclosure.
Javid Hussain - @javidhussain21: Meldung von XSS Schwachstellen.
Jayshree Bhattacharya - linkedin.com/in/jayshree-bhattacharya-4a399a135 - Meldung von Broken Authentication Schwachstellen.
Jeet Pal - https://www.linkedin.com/in/jeet-pal-22601a290 - Meldung von SQL injection Schwachstellen / Meldung von Stored Cross Site Scripting (XSS) Schwachstellen.
Jens Müller - hacking-printers.net – CORS Fehlkonfiguration.
Kamrul Hassan, https://www.linkedin.com/in/kamrul-hassan-x64, Sensitive Data Exposure
Kapil S. Kulkarni - Facebook: kapil.kulkarni.587 , Twitter: @kapilkulkarni91 , LinkedIn: https://www.linkedin.com/in/kapil-kulkarni-oscp-ceh-chfi-5a333763/ - Meldung einer Content Spoofing Schwachstelle
Karan Rathod https://www.linkedin.com/in/karan-rathod-35aa951b1: Meldung von Remote Code Execution, Meldung von Subdomain Takeover, Meldung von Information Disclosure Schwachstellen.
Karim Mohamed Ahmed - https://www.facebook.com/X.TiGeR.K: Meldung von XSS Schwachstellen.
Kashif Shoukat https://www.linkedin.com/in/kashif-shoukat-1o1/ - Meldung von Other Schwachstellen.
kasme_memon_aya_tha - Meldung von Remote Code Execution (RCE) Schwachstellen.
Kasper Karlsson - Meldung von Cross-site scripting (XSS) Schwachstellen.
Kaushik Sardar - https://www.facebook.com/kaushiksardar.22 - Meldung von Host Header Schwachstellen.
Kenneth Billones - https://twitter.com/k3nziy - Meldung von Open Redirect Schwachstellen.
Kevin Yehezkiel Gurning - https://www.linkedin.com/in/vinzel/ - Meldung von Open Redirect Schwachstellen, Cross-site scripting (XSS).
Keyur Mehta - linkedin.com/in/keyur-mehta4455 - Meldung von Clickjacking Schwachstellen, Meldung von Default login Schwachstellen.
Khaled Abdelaziz Youssef - Meldung von Broken Access Control und Broken Authentication Schwachstellen, Meldung von Broken Access Control Schwachstellen, Meldung von Information Disclosure Schwachstellen.
killua_21 - https://www.facebook.com/profile.php?id=100020497173263 - Meldung von Missing rate limit Schwachstellen.
Kiran Chettri - twitter.com/kiranchettri_?s=09 - Meldung von User Enumeration, verschiedenen Security misconfiguration und Possible DoS Attack Schwachstellen; Meldung von HTML/CSS injection Schwachstellen; Broken Access Control
Kishan Kumar - https://twitter.com/hst_kishan?s=09 - Meldung einer Clickjacking Schwachstelle.
Klaus @klaus_dev - Meldung von Information Disclosure Schwachstellen.
Kolozsi András https://twitter.com/bugh101 - Meldung von XSS Schwachstellen, SQLi, Information Disclosure, CSFR
kr1shna4garwal - https://www.linkedin.com/in/kr1shna4garwal - Meldung von User Enumeration Schwachstellen / Meldung von Information Disclosure Schwachstellen.
Krishna Chaitanya N - linkedin.com/in/n-krishna-chaitanya-27926aba - Meldung von Information Disclosure Schwachstellen.
Kuldeep Soni (c1ph3r) - https://www.linkedin.com/in/kuldeep-s-49108798/ - Meldung von Broken Access Control und Open Redirect Schwachstellen.
Kunal Bahl - Twitter: https://twitter.com/KunalBahl3, Facebook: https://www.facebook.com/kunal.bahl59 - Meldung einer Information Disclosure Schwachstelle.
L
Laburity - https://www.linkedin.com/company/laburity - Meldung von Information Disclosure Schwachstellen.
⛧ L∆₣₮M₳₦ ⛧ - https://x.com/08xDof20784
Lalith Rallahabandi - @Lalithr95: Meldung von XSS Schwachstellen.
Lars Heckner - mail@larsheckner.de: Log4j
Lars Morgenroth - @krankoPwnz: Meldung von Open Redirect und SQL Injection Schwachstellen.
Leonid Krolle - twitter.com/KrolleLeonid - Offenlegung der gemeldeten Informationen
Leo Starcevic - Meldung von Subdomain takeover Schwachstelle, gefundene Information Disclosure, Cross-site scripting (XSS), Unsecure communitation Schwachstellen.
Leo Switness – reportet SQL vulnerabilities.
Leonid Hartmann - https://twitter.com/_harleo - Reported Authentication Bypass and RCE vulnerabilities.
Leonid Krolle - twitter.com/KrolleLeonid - Reported information disclosure
Lifeawa lifeawa@163.com - Meldung von Cross-site scripting (XSS) Schwachstellen.
LINDAN TRI SAPUTRA - https://www.linkedin.com/in/lindantri - Meldung von Race Condition in Resend Email Feature causing OTP Spam
Lingaiah Gadam - @LingaihY - Meldung von Security misconfiguration Schwachstellen / Meldung von Information Disclosure Schwachstellen.
Lion Nagenrauft, Msg Systems AG - https://www.linkedin.com/pub/lion-nagenrauft/ - Meldung von Information Disclosure Schwachstelle.
Lokesh Bhade - https://www.linkedin.com/in/Lokeshbhade/ - Meldung von Clickjacking Schwachstellen.
Lorepoint - linkedin.com/company/lorepoint - Meldung von Information Disclosure Schwachstellen.
Lorenzo Toti (sp1nn4k3r) - https://www.linkedin.com/in/lorenzo-toti-b0a939163 - Meldung von Server-side request forgery (SSRF) Schwachstellen / Meldung von Information Disclosures Schwachstellen.
love yadav - linkedin.com/in/love-yadav-5159611a3 - Meldung von Possible DoS Attack und Missing rate limit Schwachstellen / Meldung von User Enumeration Schwachstellen / Meldung von Information Disclosures Schwachstellen / Meldung von Other Schwachstellen
Lucas Carvalho - linkedin.com/in/lucascarvalho-/ - Meldung von Open Redirect Schwachstellen.
Lukman Abdulrauf - https://x.com/bughun33er - Account takeover using default login credentials.
M
m0ssser - https://github.com/m0ssser: Meldung Information Disclosure
Maciej Wojtasik - https://www.linkedin.com/in/maciej-wojtasik-b7386b208/, https://billtech.pl/ - Meldung von Broken Access Control Schwachstellen.
Magashwarahan A - www.linkedin.com/in/magashwarahan-a-036775293/ - Meldung von Other Schwachstellen.
Magrabur Alam Sofily, @masofily, www.linkedin.com/in/magrabur-sofily - Meldung von Remote Code Execution (RCE) Schwachstellen.
Mahesh - LinkedIn: https://www.linkedin.com/in/f50c1e7y/ - Meldung von diversen Information Disclosure Schwachstellen / Meldung von Default login Schwachstellen.
Mahesh Raykar - www.linkedin.com/in/maheshraykar1997 - Meldung einer XSS Schwachstelle.
MAHIN VM - linkedin.com/in/mahin-vm-57413315a - Meldung von Clickjacking Schwachstellen.
Mahmoud Hegazy - https://twitter.com/Hegzous - Meldung von reflektiert XSS Schwachstelle.
Martin - https://twitter.com/martinbydefault - Meldung von Subdomain Takeover Schwachstelle.
Martin https://hackerone.com/mit0z - Meldung von verschiedenen Information Disclosure und Security misconfiguration Schwachstellen / Information Cross-site scripting (XSS) Schwachstellen / Meldung von Information Disclosure Schwachstellen
Martin "maride" Dessauer - Gefundene Critical Information Disclosure.
Martin Thirup Christensen - https://twitter.com/MThirup: Meldung von SQL und XSS Schwachstellen.
Martin van Wingerden - https://www.linkedin.com/in/martinvw/ - Reported "Unauthenticated DNS zone transfer (AXFR)".
Marvin Heyder – www.heyder-net.de - Meldung von Security Misconfiguration Schwachstellen.
Marwan Idrees Hasan nheli - https://www.facebook.com/marwannheli - Meldung von Clickjacking Schwachstellen.
Mateusz Goik - aliantsoft.pl: Meldung von XSS Schwachstellen.
Matthias Fetzer - https://de.linkedin.com/in/matthias-fetzer-2b930b9a: Meldung von SQL Injection.
Mathias Karlsson - https://detectify.com: Meldung von XSS Schwachstellen.
Mohamed Ragab - www.facebook.com/mohammed.ragab.562 - Meldung von reflektiert XSS Schwachstelle.
Mohamed Taha - https://www.facebook.com/mohamedtaha2001 - Meldung von Information Disclosure Schwachstellen.
Mohammed Abdelbaset Elnoby - @SymbianSyMoh (W3Pwn.com): Information disclosure, Multiple XSS vulnerabilities.
Mohammed Ahmed Nassar - FB.COM/Mohammed.Ahmed.Nassar: Meldung von XSS Schwachstellen.
Mohammed F. Al-Barbari - https://twitter.com/m4dm0e - Meldung von Cross-site scripting (XSS), Cross-site request forgery (CSRF) Schwachstellen.
Mohammed Fayez Albanna - www.facebook.com/bana2313: Meldung einer XSS Schwachstelle.
Mohammed Israil - https://twitter.com/mdisrail2468: Reported Access Policy Misconfiguration.
Mohammed Kamal Darwish (Algorithmic) - https://mkalgorithmic.blogspot.com/ - facebook.com/Mohammed.Kamal.Darwish - Meldung von ungesicherte kommunikation, Gefundene Information Disclosure.
Mohammed Magdi Shafig https://twitter.com/mohammedmagdi77 https://www.facebook.com/mohammedmagdishafig smartech.sd - Meldung von Information Disclosure Schwachstellen.
Mohammed Mido - https://www.facebook.com/Mr.notron - Missing rate limit
Mohammed Nafeed - https://www.linkedin.com/in/mohammed-nafeed-62a716250 - Reported "Sensitive Data Exposure".
Mohammed Sami facebook.com/Jizen0x01 - Meldung von Schwachstellen.
Mohammed Shine - https://twitter.com/mohammedshine8 - Meldung von Host Header Injection Schwachstellen.
Mohammed Waseyuddin - https://x.com/waseyuddin - Reported OAuth Bypass.
Mohammed Yasin https://twitter.com/DeogoYasin - Meldung von Broken Access Control Schwachstellen.
Mohamed Sakr - facebook.com/X3rrOR - Meldung von reflektiert XSS Schwachstelle.
Mohamed R. Serwah - @serwazzito0 - Meldung von reflektierten und stored XSS Schwachstellen / Meldung von Cross-site scripting (XSS) Schwachstellen.
@mohammadhdg1 web: https://infogazine.com - Meldung von SSL Poodle Schwachstelle.
Mohd Asif Khan - linkedin.com/in/mohd-asif-khan-✪-5228a9179 - Meldung von Security misconfiguration Schwachstellen.
Mohit Kumar - linkedin.com/in/mohit-kumar-4ab6b3bb - Meldung von Information Disclosure Schwachstellen.
Mohit Sahu - @mohitnitrr: Meldung von Content Spoofing.
Mohsin Khan https://twitter.com/mokhansec - Meldung von Information Disclosure Schwachstellen.
Monendra Sahu - indishell: Meldung von Content Spoofing.
Moritz Mätze - https://www.maetze.net/ - Reported "CORS Origin Validation Bypass with Credentials".
Mostafa Aboelnour - https://www.linkedin.com/in/maboelnour12/ - Meldung von Information Disclosure Schwachstellen.
Mr!dul Vohra - https://www.linkedin.com/in/mridulvohra - Meldung von Possible DoS Attack Schwachstellen.
Mr.AnonDeek (Abedalrahman aldeek) - facebook.com/Mr.AnonDeek - Meldung von reflektiert XSS Schwachstelle und CSRF Schwachstelle.
msion - msion@foxmail.com - Meldung von Cross-site scripting (XSS) Schwachstellen.
Muhammad Afaq Abid- https://www.linkedin.com/in/afaq/ - Meldung von Information Disclosure Schwachstellen.
Muhammad Billadilathof - facebook.com/ToflaXploit - Meldung von Cross-site scripting (XSS) Schwachstellen.
Muhammad Haris Aftab - linkedin.com/in/muhammad-haris-aftab-6693201a4 - Meldung von Security misconfiguration Schwachstellen.
Muhammad Julfikar Hyder https://thejulfikar.xyz - Meldung von Information Disclosure Schwachstellen.
Muhammad Sharief - https://www.linkedin.com/in/muhammad-sharief/ - Meldung von Unauthenticated API Endpoints & Misconfigurations in Production
Muhammad Waseem — https://www.linkedin.com/in/muhammadwaseem11/ — Remote Code Execution. Schwachstellen, Meldung von Information Disclosure Schwachstellen/ Meldung von RCE Schwachstellen.
Muhammed Sadettin KARATAŞ - Meldung von Cross Site Scripting und von Information Disclosure Schwachstellen.
Muskan Shaikh - https://www.linkedin.com/in/muskan-shaikh-a77b801b2- Meldung von Security misconfiguration Schwachstellen.
بسم الله الرحمن الرحيم - MuslimSec.com - Meldung von Schwachstellen Information Disclosure.
Mustafa Adam - https://www.linkedin.com/in/wadgamaraldeen/ - Meldung von Other Schwachstellen.
Mustafa Can IPEKCI - nukedx.com - Meldung von Subdomain Takeover Schwachstelle.
Mustafa Diaa - @c0braBaghdad1 - Reported XML-RPC, Information disclosure, SSTI, SSL/TLS Authentication Gap, Local File Disclosure and Source Code Disclosure Schwachstellen, veraltete Software mit Schwachstellen, Ungesicherte Zertifikate, Offenlegung von Konfigurationsdateien, XST und vollständige Pfadoffenlegung (Full Path Disclosure) / Meldung von Information Disclosure Schwachstellen.
Muzaffer Satiroglu: https://www.linkedin.com/in/muzaffer-satiroglu-8558541a5 - Meldung von Broken Authentication Schwachstellen.
N
n9h3ch0_2935 - https://x.com/nadhn011194 - Meldung von Default login Schwachstellen.
Naman shah - https://www.twitter.com/naman_1910 - Meldung von Broken Access Control Schwachstellen / Meldung von HTTP Header Schwachstellen..
Name – snop. – rabbitz.org: Meldung von XSS Schwachstellen.
Naresh Chowdary, twitter.com/knc331 - Meldung von Privilege escalation for server/application Schwachstellen.
Nasim Mostakim - https://www.linkedin.com/in/ontu404 - Meldung von Default Credentials Usage.
Nasreldeen Yousif Osman - LinkedIn: https://www.linkedin.com/in/nasryousif/ -Twitter: https://twitter.com/nasreldeenusif - Meldung von Cross-site scripting (XSS) Schwachstellen.
Nayab keshodwala - : https://www.linkedin.com/in/nayab-keshodwala-994b1198 - Meldung einer XSS Schwachstelle.
Neha Bhatt - https://www.linkedin.com/in/neha-b-3b7006217 - Meldung von Open Redirect Schwachstellen.
Nehal Pillai - https://www.linkedin.com/in/nehal-pillai-02a854172 - Meldung von Security misconfiguration und Broken Authentication Schwachstellen.
Nguyễn Trung Kiên (anhchangmutrang) - https://www.linkedin.com/in/anhchangmutrang - Meldung von Other Schwachstellen.
Nick Kelley - Meldung einer Full Path Disclosure Schwachstelle.
Nicolas Armua - instagram.com/thedragoncompany / https://facebook.com/DTSRECORD - Meldung von Cross-site scripting (XSS) Schwachstellen.
Nicolas Thumann – n-thumann.de - Enumeration Attack / Umgehung zweier Captchas / Falsche Konfiguration der berichteten Zugriffsrichtlinie / Meldung von Open Redirect / Meldung von reflektiert XSS Schwachstelle / /Meldung zahlreicher Information Disclosure Schwachstellen und weitere Schwachstellen / Meldung Insufficient Access Control, Information Disclosure, XSS, Account Existence Check, open redirect vulnerability / Host Header Injection and DoS Attack / DOM-XSS via File Input /Cross-site scripting (XSS)/ Domain Ownership Validation Bypass / Meldung von Open Redirect Schwachstellen/ Mögliche DoS-Attacken.
Owais Mehtab - https://twitter.com/kc_8002: Meldung von Captcha Bypass Schwachstellen.
Oyetunde Yunus - Website: https://www.coyemerald.com - Meldung von HTML Injection Schwachstellen.
P
Pablo Santiago - https://www.linkedin.com/in/pablo-s-385647163/ - Meldung von Missing rate limit, HTTP header und Server-side request forgery (SSRF) Schwachstellen.
Paras Pilani - @cool_paras): Meldung XSS Schwachstellen.
Parshwa Bhavsar - twitter.com/parshwa_bhavsar?s=08 - Meldung von HTTP header Schwachstellen.
Parth Shukla https://www.linkedin.com/in/parthshu18- Meldung von Information Disclosure Schwachstellen.
Pascal Zenker - https://parzelsec.de - @parzel2 - Meldung von RCE und SSRF Schwachstellen.
Patrick Davidson Tremblay https://www.linkedin.com/in/patrick-davidson-tremblay/ - Meldung von Default login Schwachstellen.
Patrick Lang - linkedin.com/in/patrick-lang-707809147 - Meldung von Security misconfiguration Schwachstellen / Meldung von Broken Authentication und Information Disclosure Schwachstellen.
Paul Seekamp - @nullenc0de - Meldung von Cross-site scripting (XSS) Schwachstellen.
Pedro Cardoso - twitter.com/tvmpt - Meldung von Cross-site scripting (XSS) Schwachstellen.
peterjson of RedTeam@VNG Corporation - Meldung von Remote Code Execution (RCE) Schwachstellen.
Peter Levashov - www.SeveraDAO.ai - reported Public data exposure involving OTC
Praveenarsh - https://www.instagram.com/cybersec_praveenarsh?igsh=MWp1M2E4dWZ6dHdmbQ== - Meldung von Unsecured communication Schwachstellen.
Peter Jaric - @peterjaric (javahacker.com): Meldung XSS Schwachstellen.
Philippe Delteil @philippedelteil - Meldung von Possible DoS Attack und Server-side request forgery (SSRF) Schwachstellen.
Piotr Karolak, https://github.com/UGF0aWVudF9aZXJv - Meldung von Cross-site scripting (XSS) Schwachstellen / Meldung von Server-side request forgery (SSRF) Schwachstellen / Meldung von Broken Access Control Schwachstellen.
Pritam Dash - https://www.linkedin.com/in/pritam-dash-116931171/ - Meldung von Information Disclosure, Security Misconfiguration, User Enumeration Schwachstellen.
Pradeep Jairamani: Meldung von Sicherheitsschwachstellen.
Rameshunlocked - https://x.com/RameshKanna05 - Meldung von Default login Schwachstellen.
Ramesh kanna M -Twitter account : https://twitter.com/RameshKanna05 - Meldung von Information Disclosure Schwachstellen / Meldung von Default login Schwachstellen.
Ramkumar G - twitter: https://twitter.com/_ramkumar_g - Meldung von HTML/CSS injection Schwachstellen.
Ramon Dunker - https://ramondunker.nl / https://www.linkedin.com/in/ramondunker - Meldung von Cross-site scripting (XSS) und Information-disclosure Schwachstellen, Clickjacking und Server-side request forgery (SSRF), Remote Code Execution (RCE) / Meldung von anderen Schwachstellen
Randi Julianto - https://www.linkedin.com/in/randi-julianto-182b04120 - Meldung von Clickjacking Schwachstellen.
Rasel Mir - https://www.linkedin.com/in/araselmir/ - Meldung von "Unauthenticated Access to Management API".
Raunak Gupta - https://www.linkedin.com/in/raunak-gupta-772408255/ - Meldung von Public OBS Buckets Expose Build Artifacts, Root Password Hash, and Internal Infrastructure
RAVI ASHOK PRAJAPATI - https://twitter.com/raviakp1004 https://www.linkedin.com/in/ravi-prajapati-346b15190 - Meldung von Cross-site scripting (XSS) Schwachstellen.
Ravi Pandey - https://www.linkedin.com/in/ravipandey035/ - Meldung von Security misconfiguration Schwachstellen.
Ravi Pavan - linkedin.com/in/contact-pavan - Meldung von Information Disclosure Schwachstellen.
Ravinsta Antony - Meldung von Information Disclosure Schwachstellen.
RAY - Meldung nicht signierter SAML Assertion Forgery (Full Auth Bypass).
Riya Nair - LinkedIn: https://www.linkedin.com/in/riya-nair-70a347202 - Meldung von Information Disclosure Schwachstellen.
Rizz Shinigami - https://www.linkedin.com/in/nomanpatel01?utm_source=share&utm_campaign=share_via&utm_content=profile&utm_medium=ios_app
- Meldung von Subdomain takeover Schwachstellen.
Robert Kugler - robert.kugler10@gmail.com - Meldung von Open Redirect Schwachstelle.
Robert Scherer - www.linkedin.com/in/robert-scherer-71901a26b - Meldung von Broken Access Control Schwachstellen.
Robin Descamps - https://www.linkedin.com/in/robindescamps- Meldung von Broken Authentication Schwachstellen, Server-side request forgery (SSRF).
Robin Lindner - Lindner IT - https://lindnerit.io - Meldung von Default login Schwachstellen.
Rody Shahnazarian https://twitter.com/komradz86 - Meldung von Cross-site scripting (XSS) Schwachstellen.
Rohan Agarwal - linkedin.com/in/rohan-agarwal-27265a176 - Meldung von Security misconfiguration Schwachstellen.
Rohan Kulkarni - https://www.linkedin.com/in/rohan-kulkarni-6a073979/ - Meldung von Denial of Service Schwachstellen.
Rohit pawar - https://www.linkedin.com/in/ethicalrohitt - Reported Chatbot Prompt Injection Vulnerability", SSRF and "Stored Cross Site Scripting"x(2) and "Unauthorized Redirection of Email", "Unauthorized AI Agent Creation, Marketplace Publishing, and Runtime System Prompt Disclosure" and "Unauthenticated Command Execution Through AEM".
Roman Stühler - https://stuehler-training.de - Meldung von RCE.
Ronak Nahar - Gefundene Information Disclosure.
Roy Jansen - https://www.facebook.com/RoyJansen01 - Meldung von Open Redirect Schwachstelle.
Rudra16 twitter.com/rudra16t - Meldung von Information Disclosure Schwachstellen.
Rudra Karn - @rudra11346926 - Meldung von Information Disclosure Schwachstellen.
Rupesh Tanaji Kokare - https://www.linkedin.com/in/rupesh-kokare-b63a78145/ - Meldung von Clickjacking Schwachstelle.
S
Şaban Göktürk - https://x.com/mxroot https://www.linkedin.com/in/sabangokturk - Meldung von Information Disclosure und Cross-site scripting (XSS) Schwachstellen, Meldung von HTML/CSS injection und Open Redirect Schwachstellen.
Sabir Ali - https://x.com/0xSabir - Reported "Unauthenticated Exposure of User Emails and Phone Numbers"
SADDAM HUSSAIN - https://twitter.com/wisdomfreak1 - Meldung von Information Disclosure Schwachstellen.
SAFA Ayoub - Twitter: @SafaAyoub - Meldung von Information Disclosure, RCE und SQLI Schwachstellen.
Saif Abdullah Khan Mahi - https://x.com/badhacker0x1 - Meldung von reflected Cross-site scripting (XSS) Schwachstellen / Meldung von Other Schwachstellen.
SAIGANESH MARATI - https://www.linkedin.com/in/saiganesh-marati-739492214 - Meldung von diversen Clickjacking Schwachstellen / Meldung von Information Disclosure Schwachstellen / Meldung von HTTP header Schwachstellen.
Sajal Verma - https://www.facebook.com/sajalpentest: Meldung von information disclosure Schwachstellen.
Samet Şahin - https://twitter.com/F4LCONE_/ https://www.linkedin.com/in/sametsahinn/- Meldung von XSS Schwachstellen.
Samprit Das - https://www.linkedin.com/in/samprit-das-9805831a2
- Meldung von Server-side request forgery (SSRF) Schwachstellen / Meldung von Cross-site scripting (XSS) Schwachstellen.
SAMWEL SENSO MWITA - https://www.linkedin.com/in/samwel-senso-0a5094325/ - Reported "Information Disclosure via Internal GUID Service Endpoint".
Sánchez Garcés - http://enelpc.com - @enelpc: Meldung von XSS Schwachstellen.
Sandesh Gawai - https://www.linkedin.com/in/sandeshgg - Reported Unauthenticated pprof Endpoint Leading to Credential Exposure
Sandip Oli https://www.linkedin.com/in/sandip-olee/ https://www.facebook.com/sandip.olee - Meldung von Information Disclosure und Open Redirect Schwachstellen.
https://www.linkedin.com/in/sanjay-venkatesan-5a478220b - Meldung von Information Disclosure Schwachstellen.
Sangam Goel- https://www.linkedin.com/in/sangamgoel - Meldung von Server version information disclosure / Confidential document leak.
Sanwoola Oluwaseyi Fredrick - x.com/f_r_e_d_d_y_1 - Meldung von Open Redirect Schwachstellen / Meldung von diversen Clickjacking Schwachstellen.
SecuNinja - http://twitter.com/secuninja - Meldung von XSS Schwachstellen und Fehlkonfigurationen auf Webservern / Meldung von reflektiert XSS Schwachstelle, Meldung von Information Disclosure, Meldung von Subdomain takeover Schwachstellen.
Sergio Galán aka NaxoneZ - @NaxoneZ: Meldung von XST Schwachstellen.
Severus Huy Ngo - www.linkedin.com/in/huy-ng%C3%B4-1a9b52282/ - Meldung von Information Disclosure Schwachstellen.
@serWazito0 - Meldung von Cross-site scripting (XSS) Schwachstellen.
Suyash Bavalekar - https://bugcrowd.com/Suyash_777 - Meldung von Clickjacking Schwachstelle.
Suyog Palav (S.P.) - facebook.com/suyog.palav & linkedin.com/in/suyog-palav - Meldung der Umgehung eines Sicherheitsmechanismus.
Sven Großmann - twitter.com/svennergr / https://grossmann.dev - Meldung von Critical Information Disclosure Schwachstellen.
Sven Morgenroth - @asdizzle_ http://asdizzle.com/: Meldung von XSS Schwachstellen.
Swapneil Kumar Dash - https://in.linkedin.com/in/swapneil-dash-7256a5b0 - Cross Site Scripting
Swapnil A. - Thaware - www.twitter.com/swapnilthaware: Meldung von CSRF und Clickjacking Schwachstellen.
Swathi - https://www.linkedin.com/in/pasupuleti-swathi - Meldung von Cross-site scripting (XSS) Schwachstellen.
T
Tahmid Islam - https://facebook.com/tahmidnil - Meldung von Server-side request forgery (SSRF) Schwachstellen / Meldung von Authentication Bypass Schwachstellen / Meldung von Broken Access Control Schwachstellen.
Tarikul Islam https://sa1tama0.com https://x.com/sa1tama0 https://www.linkedin.com/in/sa1tama0. Reported Reflected Cross-Site Scripting (XSS) due to Unhandled Exception in Login Form
tuo4n8 - Verichains Cyber Force - https://verichains.io - Meldung von Privilege escalation for server/application und Remote Code Execution (RCE) Schwachstellen.
Tushar Sharma - https://www.linkedin.com/in/tushar-sharma-700657139/ - Meldung von Text Injection Schwachstellen.
Tushar Vyas - @iamtusharvyas - Meldung von verschiedenen Information Disclosure Schwachstellen / Meldung von User Enumeration Schwachstellen /Meldung von HTTP header Schwachstellen / Meldung von Path traversal Schwachstellen.
Tusuubira Emmanuel (kenjoe41) - twitter.com/kenjoe41 - Meldung von Information Disclosure Schwachstellen / Meldung von User Enumeration Schwachstellen.
Vaibhav Khatke - https://in.linkedin.com/in/javaibs - Gefundene HTML Injection.
Vaibhav Lakhani - twitter.com/vlakhani28 - linkedin.com/in/vaibhav-lakhani - Meldung von Clickjacking und Cross-site scripting (XSS) Schwachstellen sowie Security misconfiguration / Meldung von Information Disclosure Schwachstellen und Data manipulation / Meldung von Broken Access Control Schwachstellen / Meldung von Information Disclosure Schwachstellen / Meldung von User Enumeration Schwachstellen.
Vaibhav Nitin Gaikwad - linkedin.com/in/vaibhav-gaikwad-55071b152 - Meldung von Information Disclosure Schwachstellen.
Vaibhav Shinde - LinkedIn https://www.linkedin.com/in/vaibhav-shinde-28b811242 - Meldung von ausgelaufenen Zertifikaten.
Vaidik Pandya (h4x0r_fr34k) - linkedin.com/in/vaidikpandya - WEB/LINKEDIN/TWITTER/FB - Meldung von Default login Schwachstellen und Cross-site scripting (XSS) / Meldung von Server-side request forgery (SSRF) Schwachstellen.
Vaisha Bernard - https://www.linkedin.com/in/vaishabernard/ - Meldung von Authentication Bypass.
Vedachala - @vedachalaka: Meldung von Clickjacking Schwachstellen.
Vedant Shinde https://www.linkedin.com/in/vedantshinde15 - Meldung von Clickjacking Schwachstellen.
VEDHA PRAKASH ACHARY TALLOJU - @iamvedhaprakash - Meldung von Clickjacking / Meldung von HTTP Header Injection Schwachstellen.
Veli-Pekka Vainio: Meldung von XSS Schwachstellen.
Venkata Sateesh Netti - https://twitter.com/str4n63r - Meldung von Other Schwachstellen.
Venkateswara Reddy Yaruva & Abhijeth D: Meldung von XSS Schwachstellen.
Victor Curălea - https://twitter.com/VictorCuralea/ - Meldung von Remote Code Execution (RCE) Schwachstellen.
Vidhan thakur - LinkedIn profile: https://linkedin.com/in/vidhan-thakur - Meldung von Information disclosure and HTML Injection und Broken Authentication and Session Management > Failure to Invalidate Session.
Vikash Chaudhary – URL: www.hackersera.in - Meldung von XSS Schwachstellen.
Vikas Srivastava, India https://www.linkedin.com/in/007vikaxh https://www.twitter.com/007vikaxh - Meldung von Information Disclosure Schwachstellen / Meldung von User Enumeration Schwachstellen / Meldung von HTTP header und Broken Access Control und Text Injection/context spoofing Schwachstellen.
Vinayak Chaturvedi - linkedin.com/in/vinayak-chaturvedi-348b071a1 - Meldung von Clickjacking Schwachstellen.
Vineet Kumar - https://bughunter.withgoogle.com/profile/80ae25f5-877d-4402-94e8-7902cacdb4b9 - Meldung von fehlerhaften DNS Einträgen.
Vinit Lakra - linkedin.com/in/vinithacker - Meldung von diversen HTTP header, Broken Access Control und Broken Authentication Schwachstellen / Meldung von Clickjacking Schwachstellen / Meldung von Open Redirect Schwachstellen / Meldung von Broken Access Control Schwachstellen / Meldung von diversen HTTP header Schwachstellen / Meldung von Missing rate limit Schwachstellen / Meldung von diversen Clickjacking Schwachstellen /Meldung von Information Disclosure Schwachstellen, / Meldung von HTML/CSS injection Schwachstellen, Cross-site scripting (XSS) und Information Disclosure Schwachstellen / Meldung von Default login Schwachstellen.
Vinod Kumar Deekonda - Meldung von Information Disclosure Schwachstellen.
Vinod Tiwari - @war_crack: Meldung von Clickjacking Schwachstellen.
Vinod Tiwari & Sumit Shinde: Meldung von ClickJacking and CSRF Schwachstellen.
Vinod Tiwari & Himanshu Thakur - Meldung von XSS Schwachstellen.
v1nzen - https://twitter.com/2021_neo - Meldung von Path traversal Schwachstellen, Meldung von Broken Access Control Schwachstellen.
Virang (imwaiting18) - linkedin.com/in/rajyaguruvirang - Meldung von Information Disclosure Schwachstellen.
Vishal Barot https://twitter.com/vflexo - Meldung von Cross-site scripting (XSS) Schwachstellen.
Vishnu Raghav - https://www.linkedin.com/in/vishnu-raghav-783162171 - Meldung von Open Redirect Schwachstellen.
Whitesector from Serbia - URL: https://whitesector.wordpress.com, Twitter: https://twitter.com/DistrictWhit3 - Meldung einer Open Redirect-Schwachstelle.
WSecure - We Secure IT - http://www.wsecure.de - Meldung von> XSS/MiTM/HSTS/CSP
wtm - http://offensi.com - Meldung von Directory Listing / Information Disclosure Schwachstellen.
WuXie - https://x.com/wuxie_sec - Meldung von Default login Schwachstellen.
Yaranis Fonseca - @GordonShomway01: Meldung von XSS Schwachstellen.
Yash kushwah - (@cyberyash951) Linkdin: https://www.linkedin.com/mwlite/in/yash-kushwah-a80449229 - Meldung von Information Disclosure und User Enumeration Schwachstellen.
Yasser Ezzat - https://twitter.com/yassergersy - Meldung von Information Disclosure Schwachstellen, HTTP header.
Yasser Janah https://www.linkedin.com/in/yasserjanah/- Meldung von Remote Code Execution (RCE) Schwachstellen.
Yebo Cao - https://www.linkedin.com/in/yebocao/ - Meldung von diversen Information Disclosure Schwachstellen.
Yogeesh Seralathan - @y0g1337h: Meldung von XSS Schwachstellen.
Yousef Mohamed - linkedin.com/in/yousef-mohamed-124484203 - Meldung von Default login und Cross-site scripting (XSS) Schwachstellen, Security misconfiguration.
Yousef Mohamed - linkedin.com/in/yousef-mohamed15 - Meldung von diversen Broken Authentication Schwachstellen und Server Security Misconfiguration > Using Default Credentials, Authentication bypass
Youssef Ahmed (yghonem) - https://www.facebook.com/yghonem14 - Meldung von Missing rate limit Schwachstelle.
Youssef A. Mohamed - generaleg0x01.com - Meldung von Arbitrary File Upload.
Youssef ABYAA - https://twitter.com/josef0x - Meldung von Open Redirect.
Yukesh Kumar [ 3th1c_yuk1 ] - Meldung von Information Disclosure Schwachstellen.
Yunus AYDIN https://twitter.com/aydinnyunuss - Meldung von Information Disclosure Schwachstellen / Meldung von SQL Injection / Meldung von Possible DoS Attack Schwachstellen.
Yunus YILMAZ - https://twitter.com/ynsy34 - Meldung von reflektiert XSS Schwachstelle / Gefundene Open Redirect / Meldung von Security misconfiguration Schwachstellen.
Yusuf Abdulmalik Adeolu - Twitter: https://x.com/cybersage112?s=21 - Information Disclosure
Z
Zachary S. Stashis @Nu11ifidian https://redseersecurity.com/ https://www.linkedin.com/in/zacharysstashis/ - Meldung von verschiedenen Information Disclosure und verschiedene Open Redirect Schwachstellen/ Meldung von HTTP header Schwachstellen/ Meldung von Broken Access Control Schwachstellen.
Zhenwarx - Twitter.com/ZhenwarX - Meldung von Information Disclosure Schwachstellen; Open Redirect.
Zin Min Phyo - x.com/zin_min_phyo - Reported Remote Code Execution and Secret Disclosure / Reported Reflected DOM-based XSS / Reported Clickjacking/ Reported "Unauthenticated Access to Business Customer Support Data" / Reported "Error-Based SQL Injection"/ Reported "Open redirect on the logout flow of the application via a parameter", Reported "Unauthenticated PII Disclosure", Reported " Disclosure of Secrets for Publicly Accessible Asset".
Zoltan Panczel - https://twitter.com/SilentSignalHU - Meldung von XXE und File Inclusion Schwachstellen.
ZSEC Red Team - https://hackerone.com/zalogroup - Meldung von Server-side request forgery (SSRF) Schwachstellen.
Zythop - twitter.com/HaboubiAnis - Meldung von Path traversal Schwachstellen.