Page 1 of 1

How to report xss which requires account with username and password ?

Posted: Mon Dec 12, 2016 6:49 am
by yvtale
Dear Admin,
Is there need to submit credential like username and password at a time of manual submission ? :?:
What if reporter not willing to submit his credential ? :D
I mean, what if I want to submit XSS on website abc.com and I have account whoes password and username I don't want to disclose.
Then is there way to submit report, Please let us know ! :)

Re: How to report xss which requires account with username and password ?

Posted: Mon Dec 12, 2016 7:23 am
by tbmnull
create a new disposable user

Re: How to report xss which requires account with username and password ?

Posted: Mon Dec 12, 2016 7:51 am
by x1admin
tbmnull wrote:create a new disposable user
yes this is best way

Re: How to report xss which requires account with username and password ?

Posted: Mon Dec 12, 2016 8:44 am
by yvtale
x1admin wrote:
tbmnull wrote:create a new disposable user
yes this is best way
Absolutely..Earlier I was trying with the same way..But this time the case is different like the website requires high subscription fee (So there is no way to make disposable user as tbm,admin suggested) and account is of my teacher so I'm not willing to share it anyway..
Can I put credential inside https://privnote.com/ and share it..but is there guarantee from moderator that they will not use it further.

(To dear tbm and admin, I'm sorry guys, I have fully confidence and trust on you both (I have also shared lots of credential with admin before) but my teacher don't want to share his account :D )

Any suggestion please ? :roll:

Re: How to report xss which requires account with username and password ?

Posted: Mon Dec 12, 2016 10:40 am
by tbmnull
directly contact to privnote, maybe they reward you! (I hope)

Re: How to report xss which requires account with username and password ?

Posted: Mon Dec 12, 2016 10:50 am
by yvtale
tbmnull wrote:directly contact to privnote, maybe they reward you! (I hope)
Ok..but It was another website..BTW.. Thanks for help @tbm, @admin !
I'll contact them directly..