Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

$6k for an internal perimiter SSRF that led to source code access? What a joke.


Is that not the "XML External Entity processing to Blind SSRF on Java Management API" SSRF? As that would make sense to match that payment. I really struggle to believe that the $6k is for the maven access one, that's a billion dollar vulnerability.


That’s not a billion dollar vulnerability, you can buy recent copies of this source code for a million dollars.


A million dollars for iOS's source code?


Yeah. This stuff gets traded all the time.


Where can I read more about this?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: