<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[RSS Feed]]></title><description><![CDATA[RSS Feed]]></description><link>http://direct.ecency.com</link><image><url>http://direct.ecency.com/logo512.png</url><title>RSS Feed</title><link>http://direct.ecency.com</link></image><generator>RSS for Node</generator><lastBuildDate>Wed, 06 May 2026 17:53:13 GMT</lastBuildDate><atom:link href="http://direct.ecency.com/@spaced/rss" rel="self" type="application/rss+xml"/><item><title><![CDATA[[AMA I hunt BUGS, and collect BUG BOUNTYs] Hello Everyone,  please read this, it took two years to find two of these, and I'm back and finding the SECOND CRITICAL XSS bug in steemit.com. Please READ & afterwards vote up for attention]]></title><description><![CDATA[SECURE DISCLOSURE With issues like these, it can be hard to get the attention of those who need to know, I have sent emails to Ned, but I'm not in the inner circle. I mostly just hang out on Steemit and]]></description><link>http://direct.ecency.com/steem/@spaced/ama-i-hunt-bugs-and-collect-bug-bountys-hello-everyone-please-read-this-it-took-two-years-to-find-two-of-these-and-i-m-back-and</link><guid isPermaLink="true">http://direct.ecency.com/steem/@spaced/ama-i-hunt-bugs-and-collect-bug-bountys-hello-everyone-please-read-this-it-took-two-years-to-find-two-of-these-and-i-m-back-and</guid><category><![CDATA[steem]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Tue, 28 Aug 2018 21:55:30 GMT</pubDate></item><item><title><![CDATA[utf8 is hard :)]]></title><description><![CDATA[test]]></description><link>http://direct.ecency.com/test/@spaced/utf8-is-hard</link><guid isPermaLink="true">http://direct.ecency.com/test/@spaced/utf8-is-hard</guid><category><![CDATA[test]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Fri, 15 Dec 2017 02:18:06 GMT</pubDate></item><item><title><![CDATA[I have one working XSS, admins please contact me, it may not be safe to use this site atm]]></title><description><![CDATA[You remember what happened last time an XSS was found right? Admins lost their accounts and were posting fake messages and stealing money and spamming? I think this could happen again.]]></description><link>http://direct.ecency.com/security/@spaced/i-have-one-working-xss-admins-please-contact-me-it-may-not-be-safe-to-use-this-site-atm</link><guid isPermaLink="true">http://direct.ecency.com/security/@spaced/i-have-one-working-xss-admins-please-contact-me-it-may-not-be-safe-to-use-this-site-atm</guid><category><![CDATA[security]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Fri, 15 Dec 2017 02:12:57 GMT</pubDate></item><item><title><![CDATA[test]]></title><description><![CDATA[lol dont think you should be able to do that dont click on anything, probably should avoid this page, unless i deleted it]]></description><link>http://direct.ecency.com/test/@spaced/4ymzmp-test</link><guid isPermaLink="true">http://direct.ecency.com/test/@spaced/4ymzmp-test</guid><category><![CDATA[test]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Fri, 15 Dec 2017 01:59:39 GMT</pubDate></item><item><title><![CDATA[test]]></title><description><![CDATA[sdfsdf sdf dsf sd f sdf sdf s f ds]]></description><link>http://direct.ecency.com/test/@spaced/2ha8jj-test</link><guid isPermaLink="true">http://direct.ecency.com/test/@spaced/2ha8jj-test</guid><category><![CDATA[test]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Tue, 13 Jun 2017 22:16:18 GMT</pubDate></item><item><title><![CDATA[[Bug Report] I found an XSS attack in the new profile settings but because Steemit community is so awesome and a self healing organism I'm going to report it privately because the community rewards white hats]]></title><description><![CDATA[I have reported several bugs, most don't receive much but when an article telling hackers to report bugs instead of using the hacks got 3,000 USD in rewards while my reporting of dangerous bugs was getting]]></description><link>http://direct.ecency.com/steemit/@spaced/pzr58-bug-report-i-found-an-xss-attack-in-the-new-profile-settings-but-because-steemit-community-is-so-awesome-and-a-self-healing</link><guid isPermaLink="true">http://direct.ecency.com/steemit/@spaced/pzr58-bug-report-i-found-an-xss-attack-in-the-new-profile-settings-but-because-steemit-community-is-so-awesome-and-a-self-healing</guid><category><![CDATA[steemit]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Mon, 12 Jun 2017 11:59:48 GMT</pubDate></item><item><title><![CDATA[[Bug Report] I found an XSS attack in the new profile settings but because Steemit community is so awesome and a self healing organism I'm going to report it privately because the community rewards white hats]]></title><description><![CDATA[I have reported several bugs, most don't receive much but when an article telling hackers to report bugs instead of using the hacks got 3,000 USD in rewards while my reporting of dangerous bugs was getting]]></description><link>http://direct.ecency.com/test/@spaced/bug-report-i-found-an-xss-attack-in-the-new-profile-settings-but-because-steemit-community-is-so-awesome-and-a-self-healing</link><guid isPermaLink="true">http://direct.ecency.com/test/@spaced/bug-report-i-found-an-xss-attack-in-the-new-profile-settings-but-because-steemit-community-is-so-awesome-and-a-self-healing</guid><category><![CDATA[test]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Mon, 12 Jun 2017 11:53:12 GMT</pubDate></item><item><title><![CDATA[\\\\\\\\\art\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\]]></title><link>http://direct.ecency.com/test/@spaced/less-than-pre-greater-than-less-than-img-less-than-script-greater-than-document-write-less-than-scri-less-than-script-greater</link><guid isPermaLink="true">http://direct.ecency.com/test/@spaced/less-than-pre-greater-than-less-than-img-less-than-script-greater-than-document-write-less-than-scri-less-than-script-greater</guid><category><![CDATA[test]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Thu, 13 Oct 2016 10:16:06 GMT</pubDate></item><item><title><![CDATA[[Bug Report] I found a JS DOS]]></title><description><![CDATA[\t<!---<div style=" "]]></description><link>http://direct.ecency.com/steemit/@spaced/bug-report-i-found-a-js-dos</link><guid isPermaLink="true">http://direct.ecency.com/steemit/@spaced/bug-report-i-found-a-js-dos</guid><category><![CDATA[steemit]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Mon, 25 Jul 2016 08:27:57 GMT</pubDate></item><item><title><![CDATA[Why did a post telling people to report bugs make 3,000 USD in upvotes and my actual post about a legitimate security issue that the developers directly thanked me get less than 100 USD?]]></title><description><![CDATA[I wrote these two posts before the hack: [Security/Bug Report] Steemit.com is vulnerable to "Slow Post" and "Slowloris" DOS attacks Steemit.com Administrators: You should not allow]]></description><link>http://direct.ecency.com/steem/@spaced/why-did-a-post-telling-people-to-report-bugs-make-3-000-usd-in-upvotes-and-my-actual-post-about-a-legitimate-security-issue-that</link><guid isPermaLink="true">http://direct.ecency.com/steem/@spaced/why-did-a-post-telling-people-to-report-bugs-make-3-000-usd-in-upvotes-and-my-actual-post-about-a-legitimate-security-issue-that</guid><category><![CDATA[steem]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Sun, 17 Jul 2016 03:24:51 GMT</pubDate></item><item><title><![CDATA[testing testing testing]]></title><description><![CDATA[testing]]></description><link>http://direct.ecency.com/test/@spaced/testing-testing-testing</link><guid isPermaLink="true">http://direct.ecency.com/test/@spaced/testing-testing-testing</guid><category><![CDATA[test]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Wed, 13 Jul 2016 19:52:54 GMT</pubDate></item><item><title><![CDATA[spam]]></title><description><![CDATA[test test test]]></description><link>http://direct.ecency.com/spam/@spaced/spam</link><guid isPermaLink="true">http://direct.ecency.com/spam/@spaced/spam</guid><category><![CDATA[spam]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Wed, 13 Jul 2016 15:28:21 GMT</pubDate></item><item><title><![CDATA[[Security/Bug Report] Steemit.com is vulnerable to "Slow Post" and "Slowloris" DOS attacks]]></title><description><![CDATA[Introduction As some may have seen, the site has been going off line when the WebSocket server throws an internal service error 500. This is due to a slowloris type attack against the WebSocket connection.]]></description><link>http://direct.ecency.com/steemit/@spaced/5p9jb-security-bug-report-steemit-com-is-vulnerable-to-slow-post-and-slowloris-dos-attacks</link><guid isPermaLink="true">http://direct.ecency.com/steemit/@spaced/5p9jb-security-bug-report-steemit-com-is-vulnerable-to-slow-post-and-slowloris-dos-attacks</guid><category><![CDATA[steemit]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Wed, 13 Jul 2016 15:16:15 GMT</pubDate></item><item><title><![CDATA[1]]></title><description><![CDATA[1]]></description><link>http://direct.ecency.com/security/@spaced/2c6ery-security-bug-report-steemit-com-is-vulnerable-to-slow-post-and-slowloris-dos-attacks</link><guid isPermaLink="true">http://direct.ecency.com/security/@spaced/2c6ery-security-bug-report-steemit-com-is-vulnerable-to-slow-post-and-slowloris-dos-attacks</guid><category><![CDATA[security]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Wed, 13 Jul 2016 15:11:03 GMT</pubDate></item><item><title><![CDATA[[Security/Bug Report] Steemit.com is vulnerable to "Slow Post" and "Slowloris" DOS attacks]]></title><description><![CDATA[Introduction As some may have seen, the site has been going off line when the WebSocket server throws an internal service error 500. This is due to a slowloris type attack against the WebSocket connection.]]></description><link>http://direct.ecency.com/security/@spaced/security-bug-report-steemit-com-is-vulnerable-to-slow-post-and-slowloris-dos-attacks</link><guid isPermaLink="true">http://direct.ecency.com/security/@spaced/security-bug-report-steemit-com-is-vulnerable-to-slow-post-and-slowloris-dos-attacks</guid><category><![CDATA[security]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Wed, 13 Jul 2016 13:37:18 GMT</pubDate></item><item><title><![CDATA[New users will rightfully view this community as sexist, we are creating economic incentives for woman to present themselves solely as sexual objects. Instead we should reward woman who post intellectual content.]]></title><description><![CDATA[We can fix this as a community and porn is already free on the Internet. That is all.]]></description><link>http://direct.ecency.com/steemit/@spaced/new-users-will-rightfully-view-this-community-as-sexist-we-are-creating-economic-incentives-for-woman-to-present-themselves</link><guid isPermaLink="true">http://direct.ecency.com/steemit/@spaced/new-users-will-rightfully-view-this-community-as-sexist-we-are-creating-economic-incentives-for-woman-to-present-themselves</guid><category><![CDATA[steemit]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Wed, 13 Jul 2016 12:21:39 GMT</pubDate></item><item><title><![CDATA[Can we please stop being sexist as a community, we are creating economic incentives for woman to present themselves solely as sexual objects. Instead we should reward woman who post intellectual content.]]></title><description><![CDATA[We can fix this as a community and porn is already free on the internet. That is all.]]></description><link>http://direct.ecency.com/steem/@spaced/can-we-please-stop-being-sexist-as-a-community-we-are-creating-economic-incentives-for-woman-to-present-themselves-solely-as</link><guid isPermaLink="true">http://direct.ecency.com/steem/@spaced/can-we-please-stop-being-sexist-as-a-community-we-are-creating-economic-incentives-for-woman-to-present-themselves-solely-as</guid><category><![CDATA[steem]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Wed, 13 Jul 2016 11:08:09 GMT</pubDate></item><item><title><![CDATA[Know Go Lang? Help out with the new Go RPC client go-steem/rpc]]></title><description><![CDATA[It is function but it needs a lot of love. It would be nice to get this to be on par with piston. Things that need to be done: Write tests for existing code Add the capability to build transactions Add]]></description><link>http://direct.ecency.com/steem/@spaced/know-go-lang-help-out-with-the-new-go-rpc-client-go-steem-rpc</link><guid isPermaLink="true">http://direct.ecency.com/steem/@spaced/know-go-lang-help-out-with-the-new-go-rpc-client-go-steem-rpc</guid><category><![CDATA[steem]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Wed, 13 Jul 2016 05:06:45 GMT</pubDate></item><item><title><![CDATA[Test]]></title><description><![CDATA[Test post]]></description><link>http://direct.ecency.com/test/@spaced/test</link><guid isPermaLink="true">http://direct.ecency.com/test/@spaced/test</guid><category><![CDATA[test]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Wed, 13 Jul 2016 03:56:06 GMT</pubDate></item><item><title><![CDATA[Why are steem and steem dollars separate tokens?]]></title><description><![CDATA[Can anyone direct to me to the documentation that explains why steem and steem dollars are separate tokens. I have a hard time understanding why its not just Steem and Steem Power wtihout Steem dollars.]]></description><link>http://direct.ecency.com/steem/@spaced/why-are-steem-and-steem-dollars-separate-tokens</link><guid isPermaLink="true">http://direct.ecency.com/steem/@spaced/why-are-steem-and-steem-dollars-separate-tokens</guid><category><![CDATA[steem]]></category><dc:creator><![CDATA[spaced]]></dc:creator><pubDate>Wed, 13 Jul 2016 02:27:00 GMT</pubDate></item></channel></rss>