r/hacking 1h ago

Vulnerability EVERYTHING is vulnerable

Upvotes

I had posted before about how easy it is to get bug bounties. How its the most underrated way to get your foot in the door. And again and again people told me no its not easy. Yes it is.

I audit a lot of repos and here's my dashboard (this is all just from last month):

To prove it I set out to find some volunteers to have their repo scanned (applause to them for being brave in letting me publicly roast their security posture).

I ran the process in a very open way so that people could see. You can audit every single one of these findings (albeit some may be fixed): https://www.reddit.com/r/vibecoding/comments/1w04gny/comment/p72mszw/?context=1&screen_view_count=2&ext-referrer=DIRECT

And here are the results:

Leaderboard

repo total findings Critical High Medium Low Info
enve book (reddit is not letting me paste in the link. idk why) 499 3 26 23 0 447
https://github.com/rrhoopes3/Grok-Party-Pack 154 1 37 14 23 79
https://github.com/ubermuda/loupe 77 0 14 10 13 40
https://github.com/VIDGuide/dogwatch 76 0 0 19 12 45
https://github.com/homeassistant-extras/pi-hole-card 71 0 0 3 5 63
https://github.com/GChavez0210/NetPulse 60 0 1 3 1 55
https://github.com/shaqkao/screenshotify 36 0 0 2 6 28
ps://github.com/mencelot/DK2-Remix-Predetermined-Hashing 28 0 0 1 0 27
https://github.com/thecyborgcoder/2026-world-cup-simulation 18 0 1 5 0 12
https://github.com/ghreprimand/odytty 13 0 2 3 1 7
https://github.com/gtited-jpg/DaemonCore-Linux-Distro 10 0 1 6 3 0
ttps://github.com/KrystalUnity/krystal-loop-protocol 8 8 8 1 0 7
https://github.com/8exgh/meeting-alert 6 0 0 0 5 1

What should I do next? See if I can get someone to beat the Leaderboard's high score? Give up?

edit since I should have credited them: tool used is https://swifi.ai.


r/hacking 8h ago

News Uk plans safeguards to stop terrorists using AI for bioweapons

Thumbnail
bloomberg.com
4 Upvotes

r/hacking 1h ago

Question how do y'all pull IP 's/info from a spoofed caller id?

Thumbnail
Upvotes

mods I apologize if this isn't allowed here but I read the rules and I'm pre sure it is.


r/hacking 3h ago

Owning ChatGPT's Secure Sandbox

Thumbnail
joinpwn.com
1 Upvotes

r/hacking 3h ago

What extensions do you hackers use?

Thumbnail
0 Upvotes

r/hacking 3h ago

Ok..we'll skip ahead then.

0 Upvotes

You guys are fucking ruthless Alright, I get it. Lesson 2 was written for somebody who legitimately doesn't know what an IP address is. Since apparently everybody in here came out of the womb holding a fucking YubiKey, here's something a little more fun.

You have 10[.]20[.]30[.]77/27 on eth0, a default route through 10[.]20[.]30[.]65, and traffic destined for 10[.]20[.]30[.]95. No subnet calculator. Tell me the network address, broadcast address, usable host range, whether .95 is considered on-link, and whether that packet ever touches the default gateway. Then tell me what changes when the destination becomes 10[.]20[.]31[.]95 — specifically whose MAC address gets placed in the Ethernet frame and why. Bonus points if you can explain what happens when another host answers the ARP request before the legitimate host does.

I had to post like that...it kept getting autoblocked

If you guys think I'm some fucking vibe coder I'm not. I've been doing this shit since '04. I will teach anyone. All I want to do is help whoever wants to learn. Just ask away

Daemoncore Academy