Skip to content
Avatar
I swear there was an XSS somewhere around here...
I swear there was an XSS somewhere around here...

Sponsors

@tomnomnom @codingo @d3mondev @projectdiscovery

Achievements

Achievements

Organizations

@liberapay @securitytxt
Block or Report

Block or report EdOverflow

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
EdOverflow/README.md

Hi 👋

I am a web designer, developer, security researcher, and have experience triaging for numerous vulnerability disclosure programs. In my spare time, I enjoy swimming, photography, cinematography, and playing the guitar.

In 2017, I published an Internet Draft for a proposed standard which allows websites to define security policies called security.txt. A year later, I created Bug Bounty Guide, a launchpad for bug bounty programs and bug bounty hunters.

Pinned

  1. A proposed standard that allows websites to define security policies.

    HTML 1.5k 69

  2. "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

    2.7k 488

  3. csp Public

    Given a list of hosts, this small utility fetches all whitelisted domains from the hosts' CSPs.

    Go 94 16

  4. An OSINT tool to find contacts in order to report security vulnerabilities.

    Shell 221 45

  5. #legalbugbounty project — creating safe harbors on bug bounty programs and vulnerability disclosure programs. Authored by Amit Elazari.

    45 17

  6. Static website for security.txt.

    HTML 50 36

633 contributions in the last year

Oct Nov Dec Jan Feb Mar Apr May Jun Jul Aug Sep Oct Mon Wed Fri
Activity overview

Contribution activity

October 2021

2 contributions in private repositories Oct 8

Seeing something unexpected? Take a look at the GitHub profile guide.