Login
Discover
Waves
Decks
Plus
Login
Signup
<?xml version="1.0"
@spaced
59
http://.li\"alert(a.source)</SCRIPTCRIPT>a=/XSS/ alert(a.source)</SCRIPT>>alert(a.source)</SCRIPT>
Followers
243
Following
1
Resource Credits
Available
Used
Location
<?xml version="1.0" ?>
Website
http://.li\"alert(a.source)</SCRIPTCRIPT>a=/XSS/ alert(a.source)</SCRIPT>>alert(a.source)</SCRIPT>
Created
July 11, 2016
RSS Feed
Subscribe
Blog
Blog
Posts
Comments
Communities
Wallet
spaced
steem
2018-08-28 21:55
[AMA I hunt BUGS, and collect BUG BOUNTYs] Hello Everyone, please read this, it took two years to find two of these, and I'm back and finding the SECOND CRITICAL XSS bug in steemit.com. Please READ & afterwards vote up for attention
SECURE DISCLOSURE With issues like these, it can be hard to get the attention of those who need to know, I have sent emails to Ned, but I'm not in the inner circle. I mostly just hang out on Steemit and
$ 0.000
1
2
spaced
test
2017-12-15 02:18
utf8 is hard :)
test
$ 0.000
0
1
spaced
security
2017-12-15 02:12
I have one working XSS, admins please contact me, it may not be safe to use this site atm
You remember what happened last time an XSS was found right? Admins lost their accounts and were posting fake messages and stealing money and spamming? I think this could happen again.
$ 0.062
1
spaced
test
2017-12-15 01:59
test
lol dont think you should be able to do that dont click on anything, probably should avoid this page, unless i deleted it
$ 0.000
0
spaced
test
2017-06-13 22:16
test
sdfsdf sdf dsf sd f sdf sdf s f ds
$ 0.414
2
3
spaced
steemit
2017-06-12 11:59
[Bug Report] I found an XSS attack in the new profile settings but because Steemit community is so awesome and a self healing organism I'm going to report it privately because the community rewards white hats
I have reported several bugs, most don't receive much but when an article telling hackers to report bugs instead of using the hacks got 3,000 USD in rewards while my reporting of dangerous bugs was getting
$ 0.088
3
spaced
test
2017-06-12 11:53
[Bug Report] I found an XSS attack in the new profile settings but because Steemit community is so awesome and a self healing organism I'm going to report it privately because the community rewards white hats
I have reported several bugs, most don't receive much but when an article telling hackers to report bugs instead of using the hacks got 3,000 USD in rewards while my reporting of dangerous bugs was getting
$ 0.092
4
spaced
test
2016-10-13 10:16
\\\\\\\\\art\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
$ 0.000
14
spaced
steemit
2016-07-25 08:27
[Bug Report] I found a JS DOS
\t<!---<div style=" "
$ 278.532
31
1
spaced
steem
2016-07-17 03:24
Why did a post telling people to report bugs make 3,000 USD in upvotes and my actual post about a legitimate security issue that the developers directly thanked me get less than 100 USD?
I wrote these two posts before the hack: [Security/Bug Report] Steemit.com is vulnerable to "Slow Post" and "Slowloris" DOS attacks Steemit.com Administrators: You should not allow
$ 7,789.009
455
90
spaced
test
2016-07-13 19:52
testing testing testing
testing
$ 0.000
3
1
spaced
spam
2016-07-13 15:28
spam
test test test
$ 0.000
2
spaced
steemit
2016-07-13 15:16
[Security/Bug Report] Steemit.com is vulnerable to "Slow Post" and "Slowloris" DOS attacks
Introduction As some may have seen, the site has been going off line when the WebSocket server throws an internal service error 500. This is due to a slowloris type attack against the WebSocket connection.
$ 21.419
29
2
spaced
security
2016-07-13 15:11
1
1
$ 0.000
6
spaced
security
2016-07-13 13:37
[Security/Bug Report] Steemit.com is vulnerable to "Slow Post" and "Slowloris" DOS attacks
Introduction As some may have seen, the site has been going off line when the WebSocket server throws an internal service error 500. This is due to a slowloris type attack against the WebSocket connection.
$ 6.997
56
3
spaced
steemit
2016-07-13 12:21
New users will rightfully view this community as sexist, we are creating economic incentives for woman to present themselves solely as sexual objects. Instead we should reward woman who post intellectual content.
We can fix this as a community and porn is already free on the Internet. That is all.
$ 0.168
9
4
spaced
steem
2016-07-13 11:08
Can we please stop being sexist as a community, we are creating economic incentives for woman to present themselves solely as sexual objects. Instead we should reward woman who post intellectual content.
We can fix this as a community and porn is already free on the internet. That is all.
$ 0.075
12
spaced
steem
2016-07-13 05:06
Know Go Lang? Help out with the new Go RPC client go-steem/rpc
It is function but it needs a lot of love. It would be nice to get this to be on par with piston. Things that need to be done: Write tests for existing code Add the capability to build transactions Add
$ 0.000
5
1
spaced
test
2016-07-13 03:56
Test
Test post
$ 0.000
1
spaced
steem
2016-07-13 02:27
Why are steem and steem dollars separate tokens?
Can anyone direct to me to the documentation that explains why steem and steem dollars are separate tokens. I have a hard time understanding why its not just Steem and Steem Power wtihout Steem dollars.
$ 0.000
9
5