Rewarded By NCSC of Netherlands!

I got rewarded from the National Cyber Security Centrum (NCSC) of Netherlands for responsibly reporting a vulnerability in one their government websites. You can find out more information about their responsible disclosure over here .

large1 shortn

Thank you very much for the Reward!

Rewarded From Lumosity


Lumosity had a undiscovered DOM XSS  vulnerability during their signup process. By injecting our payload into the name field we were able to get javascript interpreted back nicely in the edit page. Here is a screenshot. Also we can change our name parameter to our XSS payload and get javascript interpreted back the same way. This is a persistent DOM XSS vulnerability. (more…)