Some rules apply, which I'll decide later, but I'm will willing to give partial credit for things like a=null-null.
-
-
-
As many people will confirm, I do pay out my bitcoin bounties/bets.
-
what's the status on this?
-
I don't understand the question.
-
did someone already win?
-
did someone do it already
-
the tweet is less than 20 minutes old. No.
-
lol just realized that sorry ... I mean someone hasn't popped this yet
#hacktheplanet
End of conversation
New conversation -
-
-
I can forge that email to say that Donna was never on the chain... if Jennifer's email was hacked as well. Count? ;-)pic.twitter.com/EwaaZ6wgQy
-
:) No, fields outside the check don't count.
-
But, but you said forge an email from http://hillaryclinton.com to podesta that validates. If I change the To and CC, it would be.
-
You have to forge the things checked by the key.
-
You didn't specify that :-P Also, you should note in your article that not everything is validated. But I agree with you.
-
ok, you may win a partial bounty yet. You are just adding To and CC fields outside the proper areas, right?
-
DM me your headers.
End of conversation
New conversation -
-
-
super lame i know, but this does pass DKIM sig check in thunderbird. base64 here http://pastebin.com/17SwGq00 pic.twitter.com/dG94f5lH8o
-
lol, no. Forging headers outside DKIM checks don't count :)
-
well, the exploit was that removed the outer DKIM message, because otherwise it's signed with another selector 20130720 on 1e100
End of conversation
New conversation -
-
-
if a nation state program was behind the theft and the turn over to WikiLeaks then that program may have stolen private key...
-
what
@randomtweeter can do does not determine what others can do. Anti-spam threat model doesn't encompass threatspic.twitter.com/4NFEBVmEgL
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.