| ▲ | helsinkiandrew 6 hours ago | |
So it went: > HEIF upload → libheif overflow → code execution on the forum → over-permissioned SSO tokens → employee ChatGPT/Codex account → connected GitHub → pull request in openai/openai Server side bounties aren't that profitable though: > A two-month project, under $3,000 in model tokens .... OpenAI paid Hacktron a $6,500 bounty for the account-takeover flaw on its side. The ideal hacker workflow would be to gain access to an account or system with model access which you can use for further hacks. | ||