Create an account

Very important

  • To access the important data of the forums, you must be active in each forum and especially in the leaks and database leaks section, send data and after sending the data and activity, data and important content will be opened and visible for you.
  • You will only see chat messages from people who are at or below your level.
  • More than 500,000 database leaks and millions of account leaks are waiting for you, so access and view with more activity.
  • Many important data are inactive and inaccessible for you, so open them with activity. (This will be done automatically)


Thread Rating:
  • 311 Vote(s) - 3.43 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Got a critical Hole on freelancer.com and Fiverr.com

#1
Hello i got a critical security hole on freelancer.com and fiverr.com,
Is there any one who is willing to be part on exploitation kindly comment down.
Reply

#2
Sorry, to confirm what you're asking. Are you looking for an account to exploit in order to demonstrate the vulnerability to collect a bug bounty ETC?
Reply

#3
Quote:Hello i got a critical security hole on freelancer.com and fiverr.com

Do you have unrestricted/elevated back-end access?
Reply

#4
Quote:(02-12-2020, 05:42 AM)mothered Wrote:

[To see links please register here]

Quote:Hello i got a critical security hole on freelancer.com and fiverr.com

Do you have unrestricted/elevated back-end access?
Hello i able to done Url tempering attack.in order to deposit virtual/fake $
Reply

#5
Quote:(04-29-2020, 02:20 AM)zorayo Wrote:

[To see links please register here]

Quote: (02-12-2020, 05:42 AM)mothered Wrote:

[To see links please register here]

Quote:Hello i got a critical security hole on freelancer.com and fiverr.com

Do you have unrestricted/elevated back-end access?
Hello i able to done Url tempering attack.in order to deposit virtual/fake $

Are you referring to web parameter tampering, by manipulating/exploiting the application data?
Reply

#6
Quote:(04-29-2020, 08:43 AM)mothered Wrote:

[To see links please register here]

Quote: (04-29-2020, 02:20 AM)zorayo Wrote:

[To see links please register here]

Quote: (02-12-2020, 05:42 AM)mothered Wrote:

[To see links please register here]

Do you have unrestricted/elevated back-end access?
Hello i able to done Url tempering attack.in order to deposit virtual/fake $

Are you referring to web parameter tampering, by manipulating/exploiting the application data?
Able to edit the actual amount of deposit.by editing http request in order by doing Url tempering...
The hole is working on Upwork.com too[Image: 0847b62897417cd58473a1ba389602ec.jpg]


Quote: (05-01-2020, 06:03 AM)zorayo Wrote:

[To see links please register here]

Quote: (04-29-2020, 08:43 AM)mothered Wrote:

[To see links please register here]

Quote: (04-29-2020, 02:20 AM)zorayo Wrote:

[To see links please register here]

Hello i able to done Url tempering attack.in order to deposit virtual/fake $

Are you referring to web parameter tampering, by manipulating/exploiting the application data?
Able to edit the actual amount of deposit.by editing http request in order by doing Url tempering...
The hole is working on Upwork.com too[Image: 0847b62897417cd58473a1ba389602ec.jpg]
I just link my paypal account and just done deposit of $1 and while redirecting(bouncing back to the checkout page) i edit the request and make it like $1000,$2000,$3000....
The fund works to pay for any client over the freelancer platform..
Reply

#7
Where's the money coming out of? Does it come out of the paypal account you link, or does it just create the funds from thin air? Also have you cashed it out yet? How do you know that the $500 isn't just a front end display and the server has the actual value stored internally?
Reply

#8
Quote:(06-25-2020, 06:42 PM)Stratus Wrote:

[To see links please register here]

Where's the money coming out of? Does it come out of the paypal account you link, or does it just create the funds from thin air? Also have you cashed it out yet? How do you know that the $500 isn't just a front end display and the server has the actual value stored internally?
That's a great question i want to find out myself too. I'm interested in hacking these "freelancer" companies.
Reply

#9
My guess is this is just a visual bug.
The system will probably block the cashout.
Reply

#10
Sounds interesting. Have they fixed it? I don't think that such services have strong security systems. Any vulnerability can remain unfixed for months, if not years. Recently I tried to find something on

[To see links please register here]

, but they seem fine. Also, I would not expect decent bug bounty compensation from freelance services. They don't have a lot of valuable data. Compared to messengers, they have nothing at all. Maybe get some personal data of freelancers, but what's the point? Perhaps really, it was just a visual bug.
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

©0Day  2016 - 2023 | All Rights Reserved.  Made with    for the community. Connected through