Top reports from Legal Robot program at HackerOne:
- Remote Code Execution (upload) to Legal Robot - 59 upvotes, $120
- Subdomain takeover at api.legalrobot.com due to non-used domain in Modulus.io. to Legal Robot - 33 upvotes, $100
- Privilege Escalation to Admin-level Account to Legal Robot - 23 upvotes, $400
- Bypass 8 chars password complexity with 6 chars only due to insecure password reset functionaliy to Legal Robot - 19 upvotes, $40
- Intercom chat session information persists after logout to Legal Robot - 17 upvotes, $20
- Homograph IDNs displayed in Description to Legal Robot - 16 upvotes, $40
- Password complexity requirements not enforced to Legal Robot - 15 upvotes, $20
- AWS hosting bucket for Legal Robots set as public browse and list contents: s3://legalrobot to Legal Robot - 15 upvotes, $0
- Big XSS vulnerability! to Legal Robot - 14 upvotes, $0
- Legal Robot AWS S3 Bucket Directory Listing to Legal Robot - 14 upvotes, $0
- Code injection to Legal Robot - 13 upvotes, $40
- TabNabbing issue (due to taget=_blank) to Legal Robot - 13 upvotes, $20
- content spoofing to Legal Robot - 13 upvotes, $0
- 2FA Error Handling on Google Authenticator to Legal Robot - 12 upvotes, $60
- Password complexity not evenly enforced to Legal Robot - 12 upvotes, $40
- 2FA manual entry uses wrong encoding to Legal Robot - 12 upvotes, $30
- Information Disclosure on rate limit defense mechanism to Legal Robot - 12 upvotes, $20
- Near-duplicate accounts allowed with ignored email mutations to Legal Robot - 12 upvotes, $20
- AWS S3 website can't serve security headers, may allow clickjacking to Legal Robot - 11 upvotes, $40
- Update any profile to Legal Robot - 10 upvotes, $100
- Logic issue in email change process to Legal Robot - 10 upvotes, $70
- Password reset access control to Legal Robot - 10 upvotes, $40
- Change password session fixed to Legal Robot - 10 upvotes, $0
- Email Length Verification to Legal Robot - 10 upvotes, $0
- I cant login to my account to Legal Robot - 10 upvotes, $0
- Failed OutLink on Terms of Service to Legal Robot - 10 upvotes, $0
- Venturebeat.com URL should be HTTPS to Legal Robot - 10 upvotes, $0
- Exposes a series of other private credentials to Legal Robot - 10 upvotes, $0
- Missing link to TOTP manual enroll option to Legal Robot - 9 upvotes, $90
- Missing restriction on string size in profile fields to Legal Robot - 9 upvotes, $40
- Information Disclosure in AWS S3 Bucket to Legal Robot - 9 upvotes, $20
- Domain takeover (legalrobot.co.za) to Legal Robot - 9 upvotes, $20
- Pages don't render in old browsers like IE11 to Legal Robot - 9 upvotes, $20
- Meta characters are not filtered into full name on profile page to Legal Robot - 9 upvotes, $20
- User Information leak allows user to bypass email verification. to Legal Robot - 8 upvotes, $120
- User Information sent to client through websockets to Legal Robot - 8 upvotes, $120
- Logic issue in email change process to Legal Robot - 8 upvotes, $60
- User enumeration to Legal Robot - 8 upvotes, $20
- [New Feature] Password history check to Legal Robot - 8 upvotes, $20
- [Cross-domain Referer leakage] Password reset token leakage via referer to Legal Robot - 8 upvotes, $20
- Improper validation of parameters while creating issues to Legal Robot - 8 upvotes, $20
- Change password logic inversion to Legal Robot - 8 upvotes, $20
- first name and last name restrictions bypass to Legal Robot - 8 upvotes, $20
- News Feed Detected to Legal Robot - 8 upvotes, $0
- design issue exists on login page to Legal Robot - 8 upvotes, $0
- External links to be in HTTP to Legal Robot - 8 upvotes, $0
- Legal Robot to Legal Robot - 8 upvotes, $0
- Clickjacking in Legalrobot app to Legal Robot - 8 upvotes, $0
- Missing link to 2FA recovery code to Legal Robot - 7 upvotes, $90
- Validation bypass on user profile to Legal Robot - 7 upvotes, $60
- Token leakage by referrer to Legal Robot - 7 upvotes, $60
- No notification on change password feature to Legal Robot - 7 upvotes, $20
- Profile shows incorrect account creation date to Legal Robot - 7 upvotes, $20
- Password reset token issue to Legal Robot - 7 upvotes, $20
- User enumeration from failed login error message to Legal Robot - 7 upvotes, $20
- UI Redressing ( ClickJacking ) Issue on Information submit form to Legal Robot - 7 upvotes, $0
- 2FA user enumeration via password reset to Legal Robot - 6 upvotes, $90
- Non-functional 2FA recovery codes to Legal Robot - 6 upvotes, $60
- Enhancement: email confirmation for 2FA recovery to Legal Robot - 6 upvotes, $60
- Missing Issuer parameter on TOTP 2FA to Legal Robot - 6 upvotes, $60
- Missing access control at password change to Legal Robot - 6 upvotes, $40
- CSRF to Legal Robot - 6 upvotes, $20
- SSL Issue on legalrobot.com to Legal Robot - 6 upvotes, $20
- CORS (Cross-Origin Resource Sharing) to Legal Robot - 6 upvotes, $20
- Profile fields validation bypass to Legal Robot - 6 upvotes, $20
- 2 vulns to Legal Robot - 6 upvotes, $0
- Server version disclosure to Legal Robot - 6 upvotes, $0
- 2FA user enumeration via login to Legal Robot - 6 upvotes, $0
- observer.com URL should HTTPS to Legal Robot - 6 upvotes, $0
- Futureoflife organization URL should be HTTPS to Legal Robot - 6 upvotes, $0
- No notification of change email feature to Legal Robot - 6 upvotes, $0
- Users with 2FA can have multiple sessions to Legal Robot - 5 upvotes, $60
- [UX] Notify user on likely email address typo to Legal Robot - 5 upvotes, $40
- - Guessing registered users in legalrobot.com to Legal Robot - 5 upvotes, $20
- SPF Issue to Legal Robot - 5 upvotes, $20
- CSP script-src includes "unsafe-inline" to Legal Robot - 5 upvotes, $20
- Email spoofing-fake mail from your mail domain server to Legal Robot - 5 upvotes, $0
- Click Jacking to Legal Robot - 5 upvotes, $0
- Missing homograph filter character to Legal Robot - 5 upvotes, $0
- Wrong password validation message to Legal Robot - 5 upvotes, $0
- sql injection vulnerablity found to Legal Robot - 5 upvotes, $0
- Improper Implementation of Password strength checker to Legal Robot - 5 upvotes, $0
- Registration bypass using OAuth logical bug to Legal Robot - 4 upvotes, $40
- Password reset form ignores email field to Legal Robot - 4 upvotes, $40
- Password complexity ignores empty spaces to Legal Robot - 4 upvotes, $20
- No length limit in invite_code can cause server degradation to Legal Robot - 4 upvotes, $20
- No error or notification on Reset password page to Legal Robot - 4 upvotes, $20
- Amazon Bucket Accessible (http://legalrobot.s3.amazonaws.com/) to Legal Robot - 4 upvotes, $0
- SWEET32 TLS attack to Legal Robot - 4 upvotes, $0
- Password Reset page Session Fixation to Legal Robot - 4 upvotes, $0
- UX: JS error on Password Safety link to Legal Robot - 4 upvotes, $0
- Autocomplete feature to Legal Robot - 4 upvotes, $0
- UX: JS error on Password Safety link to Legal Robot - 4 upvotes, $0
- app.legalrobot.com opens FireFox but not in FireFox ESR to Legal Robot - 4 upvotes, $0
- External links should be served in HTTPS. to Legal Robot - 4 upvotes, $0
- Broken links for stale domains may be leveraged for Phishing, Misinformation, Defaming to Legal Robot - 4 upvotes, $0
- Header Injection In app.legalrobot.com to Legal Robot - 4 upvotes, $0
- Cloudflare issue: Error 521 Ray ID: 2e7ea7f706ea4056 • 2016-09-25 12:59:55 UTC Web server is down to Legal Robot - 4 upvotes, $0
- Missing security headers, possible clickjacking to Legal Robot - 3 upvotes, $20
- Rate limiting on Email confirmation link to Legal Robot - 3 upvotes, $20
- No valid SPF record to Legal Robot - 3 upvotes, $20
- missing SPF for legalrobot.com to Legal Robot - 3 upvotes, $20
- unsecured legalrobot.co.uk assets to Legal Robot - 3 upvotes, $20
- Account profile shows encryption recovery box for all users to Legal Robot - 3 upvotes, $20
- Token leakage by referrer header & analytics to Legal Robot - 3 upvotes, $20
- Issues with Forgot password Error Handling to Legal Robot - 3 upvotes, $20
- Clickjacking: X-Frame-Options header missing to Legal Robot - 3 upvotes, $0
- Information disclosure to Legal Robot - 3 upvotes, $0
- Bypass email verification when register new account to Legal Robot - 3 upvotes, $0
- Unable to change profile picture to Legal Robot - 3 upvotes, $0
- Non-HTTPS link on blog to Legal Robot - 3 upvotes, $0
- Legal | Application is Missing CSP(Content Security Policy) Header to Legal Robot - 2 upvotes, $20
- Possible content spoofing due to missing error page to Legal Robot - 2 upvotes, $20
- Incorrect email content when disabling 2FA to Legal Robot - 2 upvotes, $20
- Lengthy manual entry of 2FA secret to Legal Robot - 2 upvotes, $20
- Incorrect error message to Legal Robot - 2 upvotes, $20
- 2FA manual entry uses wrong encoding to Legal Robot - 2 upvotes, $20
- Rate limiting on password reset links to Legal Robot - 2 upvotes, $0
- Mixed Content over HTTPS to Legal Robot - 2 upvotes, $0
- Coding error ! to Legal Robot - 2 upvotes, $0
- S3 ACL misconfiguration to Legal Robot - 2 upvotes, $0
- No alert in verify email address with wrong input to Legal Robot - 2 upvotes, $0
- Error the message with already e-mail to Legal Robot - 2 upvotes, $0
- Password Complexity to Legal Robot - 2 upvotes, $0
- Allowance of Meta/Null characters to Legal Robot - 2 upvotes, $0
- Add arbitrary value in reset password cookie to Legal Robot - 2 upvotes, $0
- Null Byte Injection in all fields of Profile to Legal Robot - 2 upvotes, $0
- Profile fields validation mismatch to Legal Robot - 1 upvotes, $20
- No DMARC Record in legalrobot-uat.com to Legal Robot - 1 upvotes, $0
- Email spoofing possible via Legal Robot domain to Legal Robot - 1 upvotes, $0
- Tampering the mail id on chatbox to Legal Robot - 1 upvotes, $0
- Weak Cryptography for Passwords to Legal Robot - 1 upvotes, $0
- The websocket traffic is not secure enough to Legal Robot - 1 upvotes, $0
- Registration Allows Disposable Email Addresses to Legal Robot - 1 upvotes, $0
- clickjacking at http://mailboxes.legalrobot-uat.com/ to Legal Robot - 1 upvotes, $0
- Information Discloser to Legal Robot - 1 upvotes, $0
- cross site web socket hijacking to Legal Robot - 1 upvotes, $0
- XSS on app.legalrobot.com to Legal Robot - 1 upvotes, $0
- Chat exposed using cookie to Legal Robot - 1 upvotes, $0
- Two accounts can be made with same password to Legal Robot - 1 upvotes, $0
- https://www.legalrobot.com/ to Legal Robot - 1 upvotes, $0
- SSL BREACH attack (CVE-2013-3587) to Legal Robot - 0 upvotes, $0
- LUCKY13 (CVE-2013-0169) effects legalrobot.com to Legal Robot - 0 upvotes, $0
- Subdomain misconfiguration [mail.legalrobot.com] to Legal Robot - 0 upvotes, $0
- Lack of input validation in e-mail & user name, job title, company name field to Legal Robot - 0 upvotes, $0
- Name can't be numbers or email to Legal Robot - 0 upvotes, $0
- Password Restriction On Change to Legal Robot - 0 upvotes, $0
- Create Api Key is not working to Legal Robot - 0 upvotes, $0
- Special characters are not filtered out on profile fields to Legal Robot - 0 upvotes, $0
- CSRF Issue to Legal Robot - 0 upvotes, $0
- Password Policy Bypass to Legal Robot - 0 upvotes, $0
- Invalid Email Verification to Legal Robot - 0 upvotes, $0
- Improper error message to Legal Robot - 0 upvotes, $0
- Cross Site WebSocket Hijacking to Legal Robot - 0 upvotes, $0
- Non-secure requests are not automatically upgraded to HTTPS to Legal Robot - 0 upvotes, $0