#AkashHamal0x01-info

1 messages ยท Page 1 of 1 (latest)

abstract musk
#

Hi, unfortunately I don't have DM enabled but if that's something sensitive you should write to Support

#

I am developer and can help with non-sensitive info here

dusky nebula
#

@abstract musk can i have a chance to speak to the program triagers?

abstract musk
#

What do you mean by program triagers?

dusky nebula
#

i mean who manage reports of stripe program through hackerone

abstract musk
#

ah jinx

dusky nebula
#

yes lol

#

hahha

#

do you manage taxjar?

abstract musk
#

I believe they are not in this Discord server. Only way is to write to Support and they will get you contact with them

dusky nebula
#

you said you are developer right?

abstract musk
#

Yep

dusky nebula
#

have you worked on taxjar project?

abstract musk
#

No, unfortunately. Any thing you can elaborate?

dusky nebula
#

yes

#

an account takeover was found on taxjar

#

the h1 triager closed as informative idk why

#

saying its intended functionality

abstract musk
#

Thanks for raising. Any email/number that may identify the conversation?

dusky nebula
#

wdym? didnt get it

abstract musk
#

I can't see that (gone) link ๐Ÿ˜…

dusky nebula
#

only visible to me and internal team of stripe who manages reports

#

we can have 1 on 1 zoom meeting so i can make you understand

#

but this is serious issue/misconfiguration

abstract musk
#

I can't do zoom, sorry ๐Ÿ˜… Please wait for a few mins

dusky nebula
#

sure do update me. and thanks!

abstract musk
#

Ok I found the internal team. Could you write into Support and describe your appeal with the report? Then tell me either email used/ticket number if any and I will connect it to the internal team reviewing hacker one reports

#

(I still need something from you and good for papertrail, so it's better to have a ticket with explanation) while here I don't have the detail thus can't just go tell the team "I have a possible vunerability but I don't know what it is"

dusky nebula
abstract musk
#

yes!

abstract musk
#

Awesome. I found it. Left an internal note already!

#

Let's wait for it to reach out to the team

dusky nebula
#

thanks and unfortunately i cannot confirm as i lost access to my 2fa app so would like to continue conversation via mail if possible and thank you so much!