Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Got a critical Hole on freelancer.com and Fiverr.com filter_list
Author
Message
Got a critical Hole on freelancer.com and Fiverr.com #1
Hello i got a critical security hole on freelancer.com and fiverr.com,
Is there any one who is willing to be part on exploitation kindly comment down.

Reply

RE: Got a critical Hole on freelancer.com and Fiverr.com #2
Sorry, to confirm what you're asking. Are you looking for an account to exploit in order to demonstrate the vulnerability to collect a bug bounty ETC?

Reply

RE: Got a critical Hole on freelancer.com and Fiverr.com #3
Quote:Hello i got a critical security hole on freelancer.com and fiverr.com

Do you have unrestricted/elevated back-end access?
[Image: AD83g1A.png]

Reply

RE: Got a critical Hole on freelancer.com and Fiverr.com #4
(02-12-2020, 05:42 AM)mothered Wrote:
Quote:Hello i got a critical security hole on freelancer.com and fiverr.com

Do you have unrestricted/elevated back-end access?
Hello i able to done Url tempering attack.in order to deposit virtual/fake $

Reply

RE: Got a critical Hole on freelancer.com and Fiverr.com #5
(04-29-2020, 02:20 AM)zorayo Wrote:
(02-12-2020, 05:42 AM)mothered Wrote:
Quote:Hello i got a critical security hole on freelancer.com and fiverr.com

Do you have unrestricted/elevated back-end access?
Hello i able to done Url tempering attack.in order to deposit virtual/fake $

Are you referring to web parameter tampering, by manipulating/exploiting the application data?
[Image: AD83g1A.png]

Reply

RE: Got a critical Hole on freelancer.com and Fiverr.com #6
(04-29-2020, 08:43 AM)mothered Wrote:
(04-29-2020, 02:20 AM)zorayo Wrote:
(02-12-2020, 05:42 AM)mothered Wrote: Do you have unrestricted/elevated back-end access?
Hello i able to done Url tempering attack.in order to deposit virtual/fake $

Are you referring to web parameter tampering, by manipulating/exploiting the application data?
Able to edit the actual amount of deposit.by editing http request in order by doing Url tempering...
The hole is working on Upwork.com too[Image: 0847b62897417cd58473a1ba389602ec.jpg]

(05-01-2020, 06:03 AM)zorayo Wrote:
(04-29-2020, 08:43 AM)mothered Wrote:
(04-29-2020, 02:20 AM)zorayo Wrote: Hello i able to done Url tempering attack.in order to deposit virtual/fake $

Are you referring to web parameter tampering, by manipulating/exploiting the application data?
Able to edit the actual amount of deposit.by editing http request in order by doing Url tempering...
The hole is working on Upwork.com too[Image: 0847b62897417cd58473a1ba389602ec.jpg]
I just link my paypal account and just done deposit of $1 and while redirecting(bouncing back to the checkout page) i edit the request and make it like $1000,$2000,$3000....
The fund works to pay for any client over the freelancer platform..
(This post was last modified: 05-01-2020, 06:05 AM by zorayo.)

Reply

RE: Got a critical Hole on freelancer.com and Fiverr.com #7
Where's the money coming out of? Does it come out of the paypal account you link, or does it just create the funds from thin air? Also have you cashed it out yet? How do you know that the $500 isn't just a front end display and the server has the actual value stored internally?

Reply

RE: Got a critical Hole on freelancer.com and Fiverr.com #8
(06-25-2020, 06:42 PM)Stratus Wrote: Where's the money coming out of? Does it come out of the paypal account you link, or does it just create the  funds from thin air? Also have you cashed it out yet? How do you know that the $500 isn't just a front end display and the server has the actual value stored internally?
That's a great question i want to find out myself too. I'm interested in hacking these "freelancer" companies. Biggrin

Reply

RE: Got a critical Hole on freelancer.com and Fiverr.com #9
My guess is this is just a visual bug.
The system will probably block the cashout.

Reply

RE: Got a critical Hole on freelancer.com and Fiverr.com #10
Sounds interesting. Have they fixed it? I don't think that such services have strong security systems. Any vulnerability can remain unfixed for months, if not years. Recently I tried to find something on ithire.com, but they seem fine. Also, I would not expect decent bug bounty compensation from freelance services. They don't have a lot of valuable data. Compared to messengers, they have nothing at all. Maybe get some personal data of freelancers, but what's the point? Perhaps really, it was just a visual bug.
(This post was last modified: 05-19-2021, 04:09 PM by Severun.)

Reply