Post B4b02jSm5Ym629CWfY by yifanlu@mastodon.social
 (DIR) More posts by yifanlu@mastodon.social
 (DIR) Post #B4SDe36rYXjKf8R9ea by yifanlu@mastodon.social
       0 likes, 1 repeats
       
       ‼️H&R Block Business 2025 Backdoor‼️I found a TLS backdoor in H&R Block software. They install a wildcard root CA (expiry 2049) into your trusted root certificate store and include the private key in the application DLL.https://www.youtube.com/watch?v=5paxvYkz1QEhttps://hrbackdoor.yifanlu.com
       
 (DIR) Post #B4Sad4NhdmopGKoday by yuri_brainwashing_co@mastodon.triggerphra.se
       0 likes, 0 repeats
       
       @yifanlu id avoid using ai for thumbnails of security disclosures, given the recent issue of spurious ai cve reports.
       
 (DIR) Post #B4TJ4ogM01NofDa3QO by endrift@social.treehouse.systems
       0 likes, 0 repeats
       
       @yifanlu I uh. Don't think that thumbnail spelled certificate right
       
 (DIR) Post #B4TJ4oymtU81aOCm9o by yifanlu@mastodon.social
       0 likes, 0 repeats
       
       @endrift look, it was either slop or a random frame and I didn't want to waste any more time on this than I already have on this useless company
       
 (DIR) Post #B4aOnpR1uGxvuJPnTE by yifanlu@mastodon.social
       0 likes, 0 repeats
       
       Lmao @Hacker0x01 told me the backdoor was known "through internal security assessments" and they're "closing this report as out of scope". But now are pissed I disclosed it. Nobody should use this joke of a platform who put the interests of companies over that of users.
       
 (DIR) Post #B4avvkqw7jfeV3v5zU by hakona@im.alstadheim.no
       0 likes, 0 repeats
       
       @yifanlu "and include the private key in the application DLL." Why are they doing that? Is the app supposed to generate new certs?
       
 (DIR) Post #B4b02jSm5Ym629CWfY by yifanlu@mastodon.social
       0 likes, 0 repeats
       
       @hakona it's for local IPC between the backend database process and the UI process they do generate a new leaf cert (and send the cert through a completely untrusted channel). My guess is they hit some warning/error about untrusted certificate and decided this was the best solution.
       
 (DIR) Post #B4cv3UrviyI1baQrwG by yifanlu@mastodon.social
       0 likes, 0 repeats
       
       Update: @Hacker0x01 replied to my email and I have my response inline. I hope this is the last I will hear about this because frankly I do not have the time or energy to care any more about this than what I have already done.
       
 (DIR) Post #B4czBosRcLRvnEtg6S by modrobert@qoto.org
       0 likes, 0 repeats
       
       @yifanlu I remember an RCE being out of scope, some of their bug bounty programs have strange conditions.
       
 (DIR) Post #B4cztcItj4obXV9dlw by modrobert@qoto.org
       0 likes, 0 repeats
       
       @yifanlu BTW: https://cybersecuritynews.com/hackerone-data-breach/
       
 (DIR) Post #B4dD7GWomZ7HSiVJmC by yifanlu@mastodon.social
       0 likes, 0 repeats
       
       🫠
       
 (DIR) Post #B4dTdeRV0Ia4AETsA4 by CliffsEsport@mastodon.social
       0 likes, 0 repeats
       
       @yifanlu its late and I might be confused, but you never were part of the program were you?  Or did you have to sign up just to report it?  I grok that was the only channel you could find to communicate it.
       
 (DIR) Post #B4dUZSEIZLZV59rwAa by yifanlu@mastodon.social
       0 likes, 0 repeats
       
       @CliffsEsport exactly, I had to sign up to report this bug. There was no mention of a bug bounty anywhere. I just wanted to disclose a vulnerability lmao
       
 (DIR) Post #B4dZf2IOP4ca9qGTzc by Slater450413@infosec.exchange
       0 likes, 0 repeats
       
       @yifanlu Cool find 😎. I learned about your disclosure this morning when it made it onto this week's #SecurityNow Ep1071 and then saw it go by here on mastodon not long after. And yes, why are commercial bug reporting platforms such a PITA to deal with trying to get someone to actually listen. Having a public reporting mechanism feels like such a "box ticking exercise" from their end.
       
 (DIR) Post #B4dpz1SkoAhadIfCYS by zopieux@mastodon.social
       0 likes, 0 repeats
       
       @yifanlu"No, I'm kicking *you* out first!" What a sad joke of a platform. It's always funny to see just how woefully ill-equipped the industry is at dealing with people who aren't solely driven by financial gain or fame.Thanks for standing tall over this mascarade and bringing this to the public.
       
 (DIR) Post #B4dtUBYHe9CMlOnjRg by carl@chaos.social
       0 likes, 0 repeats
       
       @yifanlu fragile egos
       
 (DIR) Post #B4e5jHypED2CUfBTw8 by suriele@eldritch.cafe
       0 likes, 0 repeats
       
       @yifanlu Uhm ? For real .. ?For all that moral superiority there was no attempt from you to coordinate with them either.You just took their response at face value and immediately made a video about it.No warning them you would publicly disclose if they don't confirm they will fix it, nothing .....Yeah this ain't it. Be better.All you did was put people at risk of this being used by malicious actors on them with no available patch.
       
 (DIR) Post #B4elNFTI4RjUPvbgjg by yifanlu@mastodon.social
       0 likes, 0 repeats
       
       @suriele lmao buddy lol
       
 (DIR) Post #B4gY2u62vF2dFDcgWO by elronxenu@mastodon.cloud
       0 likes, 0 repeats
       
       @yifanlu "You can't quit, we're firing you!"
       
 (DIR) Post #B4lMn8leTqQyPJAFCS by aeva@mastodon.gamedev.place
       0 likes, 0 repeats
       
       @yifanlu amazing