How to get a CVE | Methodology

  Рет қаралды 2,883

MrFreakyclown

MrFreakyclown

Күн бұрын

Ever wanted to know how you as a hacker can get a CVE assigned for a vulnerability you found during a bug bounty or penetration test? I walk you through the whole process so you can understand how and where you submit for CVE, the communication to expect and what you need to do once the CVE has been assigned.
Go here to start submitted your first CVE!
cveform.mitre.org
Leave a comment with your CVE when you get it assigned!

Пікірлер: 9
@minhld8736
@minhld8736 Жыл бұрын
Your sharing is really helpful, thank you so much!
@MrFreakyclown
@MrFreakyclown Жыл бұрын
Glad it was helpful!
@MrACG66
@MrACG66 Жыл бұрын
Thanks!
@MrFreakyclown
@MrFreakyclown Жыл бұрын
Welcome!
@elfinofficial4071
@elfinofficial4071 18 күн бұрын
I've emailed the devs, and they just don't answer, though they're active in their github issue site. They have separate email for security report. In this process do we need the dev to 1. acknowledge the vuln and 2. fix it.?
@Hexthekid
@Hexthekid Жыл бұрын
Thank you so much for this video! Just a question, what is the courtesy around submitting a cve request? ie is it better to submit before the vendor fix the vuln or after the vendor fix it? also how long does it usually take to get assigned to a CVE number? Thank you so much!
@MrFreakyclown
@MrFreakyclown Жыл бұрын
The vendor should be told before you submit. CVE can take weeks but in general I find they assigned within 24 hours.
@radharamandwivedi7609
@radharamandwivedi7609 5 ай бұрын
hey if I find a vulnerability in login pages of a public facing web app, can I get a cve for that?
@alfatech8604
@alfatech8604 3 ай бұрын
depends if they use a known cms or web framework where the vulnerability still persist on your offline or local test for example wordpress then you can get a cve but if not search for a bug bounty platform where they have assigned up for then report it there
Викторина от МАМЫ 🆘 | WICSUR #shorts
00:58
Бискас
Рет қаралды 5 МЛН
Smart Sigma Kid #funny #sigma #comedy
00:40
CRAZY GREAPA
Рет қаралды 33 МЛН
Inside Out Babies (Inside Out Animation)
00:21
FASH
Рет қаралды 23 МЛН
CVE and CVSS explained | Security Detail
3:45
Red Hat
Рет қаралды 11 М.
Easy $500 Vulnerabilities! // How To Bug Bounty
13:19
NahamSec
Рет қаралды 67 М.
How I Prepare Merge Requests: Tips From A Senior Developer
4:40
Till Carlos
Рет қаралды 1,9 М.
Detect Hackers & Malware on your Computer (literally for free)
16:38
How Hackers Move Through Networks (with Ligolo)
20:01
John Hammond
Рет қаралды 263 М.
Hacking 101: Everything You Need To Know
13:32
Privacy Matters
Рет қаралды 282 М.
Insane Vulnerability In OpenSSH Discovered
1:06:56
ThePrimeTime
Рет қаралды 171 М.
How do hackers hide themselves? - staying anonymous online
11:55
Grant Collins
Рет қаралды 1,4 МЛН
What is CVE? | Common Vulnerabilities and Exposures
5:42
Concepts Work
Рет қаралды 17 М.
Викторина от МАМЫ 🆘 | WICSUR #shorts
00:58
Бискас
Рет қаралды 5 МЛН