Skip to content

Commit 3e67d5a

Browse files
authored
Merge pull request #181 from rubygems/prv-tiny
Tiny fix for 2024-03-15-password-reset-vulnerability.md.
2 parents e55defa + bd73111 commit 3e67d5a

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

_posts/2024-03-15-password-reset-vulnerability.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ Have you ever thrown actual spaghetti at a wall? It’s funny, sticky and barely
99

1010
Running a bug bounty program means a stream of incoming reports, not all of them correct, that must be reviewed. After receiving enough dire-sounding reports that ultimately lead nowhere, it can look like thrown spaghetti (a see-what-sticks approach). Though we try to give each report a thorough, unbiased evaluation, it’s difficult to keep an open mind about any given report.
1111

12-
Dead-end reports cost the RubyGems security team time, and slow down our ability to address more urgent security issues. I once spent days working on a vulnerability and the result was “clicking that checkbox in BurpSuite invalidates this approach.
12+
Dead-end reports cost the RubyGems security team time, and slow down our ability to address more urgent security issues. I once spent days working on a vulnerability and the result was: _clicking that checkbox in BurpSuite invalidates this approach._
1313

1414
But sometimes a hacker finds a very real security issue. This is a story about a recent bug report that I almost closed, assuming it was another false alarm, and how I realized I was wrong.
1515

0 commit comments

Comments
 (0)