Scornhub - 26 May 2016
The meaning of life tastes like chicken - 24 Feb 2016
fucking astrology man - 09 Dec 2015
Freelance Consulting - 23 Nov 2015
The Wassenaar Effect - 09 Jun 2015
Scantastic! - 11 Feb 2015
It's all fucked - 05 Jan 2015
The tortured poet - 28 Dec 2014
Gone in 660 Seconds - 25 Nov 2014
College Graduation - 20 Nov 2014
Yahoo for the craic! - 21 Sep 2014
IRC what you did there... - 02 Aug 2014
Let me Bug you!? - 19 Jun 2014
Plesk 10 & 11 SSO XXE/XSS - 09 May 2014
Final Year Woes - 24 Apr 2014
SWMing in privilege, or drowning? - 10 Apr 2014
Lucid Surrealist Dreams and techno-lust. - 23 Mar 2014
New Raspberry piToy - 05 Feb 2014
Happy 2014! - 15 Jan 2014
Helpdesk Pilot Xss/CSRF Add an Admin - 30 Nov 2013
Squidoo.com $1,100 bug bounty - 02 Nov 2013
Yahoo Xss bug bounty - 01 Oct 2013
Moodle 2.0 Account Takeover - 04 Sep 2013
Xss Challenge Accepted - 17 Aug 2013
rpliy - rpi python web player - 25 Jul 2013
Busy times - 10 Jul 2013
Source Conference - 27 May 2013
Coinbase.com bug bounty - 04 May 2013
Xssive, Moodle and CSRF - 11 Apr 2013

Yahoo Pipes is Great! - 05 Mar 2013
Science Hack-day Dublin - 03 Mar 2013
Simple port scan - 26 Feb 2013
4chan-tool.py - 19 Feb 2013
Wix.com Xss - 11 Feb 2013
Crawl.py Url Crawling - 09 Feb 2013
Xssive Demo tool - 12 Jan 2013
Cyberbullying? - 27 Dec 2012
Merry XssMas - 24 Dec 2012
Watching BBC Streams - 10 Dec 2012
SWF Disassembly - 26 Nov 2012
C <3 - 16 Nov 2012
Greasemonkey XSS 2 - 21 Oct 2012
Work Logging App - 20 Oct 2012
Greasemonkey XSS - 30 Sep 2012
Guestbook XSS - 18 Sep 2012
OWASP Vicnum Project - 05 Sep 2012
August... - 05 Sep 2012
XSS Scenarios. - 30 Jul 2012
Imageroll - 06 Jul 2012
The Dangers of XSS - 14 Jun 2012

US Threat Gauge - 30 May 2012
Is this art? - 28 May 2012
Rss2Irc - 25 May 2012
Blackboard Xss Jungle - 14 May 2012
Url Info Scraper - 10 May 2012
pythonchallenge.com - 27 Apr 2012
Prime Generator - 15 Apr 2012
Sockso 1.51 Xss - 07 Apr 2012


Ubuntu 10.10 Hardening - 18 Mar 2012
2nd Year Revisited - 17 Mar 2012

Coinbase.com bug bounty

Bug bounty programs in my opinion, are a great thing. Not only do they encourage responsible vulnerability disclosure. They also provide the incentive for a company to keep active about their security. If you can implement a bug fix within a short time period, or improve your response time, you are greatly reducing the overall risk your company faces from attack both in short and in the long term. The programs can also of course benefit a company/site in other ways, as bug-finders generally would like to announce the bugs they found or the rewards the received, this in itself is providing free promotion or brand awareness!

You can find a list of already active bug bounties on These are a company that provide and run bug bounty services for other companies. A truely great idea! As a security interested individual who would like to practice their skills or fine-tune them, this provides a great opportunity to learn how to bug-hunt. The prize or reward also provides a good incentive for the effort. Breaking into the security industry isn't easy, hopefully finding a bug on a well tested, well recognized site, will help individuals find their way in.

So, how did I find my first bug bounty? Coinbase.com were recently added to the list of companies offering bounties for the bugs you find. The guidelines of their bug bounty program is here at Coinbase.com/whitehat. I hadn't previouly tried any of the bug bounties listed (aside from poking around facebook) so I thought I'd chance my arm at a newer one, since there would more than likely be more bugs since the application is in earlier days of progress.

The first thing I decided to do was have a browse through the source of the site, I'm always amazed at some of the obvious things you find in there. I opened up a javascript file that was there and began searching for strings like "location", "hash" and ".swf". I tried a few different things, then I came across the the swf file ZeroClipboard.swf. This immediately caught my eye as I was certain I'd seen it mentioned before, linked with an xss vulnerability. I went to google and found the following . I then tried the initial string and was disappointed there was no popup ;_;. Being curious I also tried the ZeroClipboard10.swf. RESULT!

I immediately emailed them. Later in the evening I received a confirmation that my bug was accepted and that I was the first to find it! Not bad for a few minutes work. I then checked my account to find my 5 Bitcoins. My first experience with a bug bounty was a good one, All I can do now is hope to find some more in my free time :D