Weekly overview of the bug-hunting category- week 52, 2018

This is a report on the weekly contributions to the bug hunting category. The post contains basic stats like the number of contributions received by the category, an excerpt on new contributors if there are any and a detailed comparison of the week's output with previous weeks.

utopian (1).jpg

Previous Reports

Bug hunting contributions summary

The contributions

ContributorURLProjectScore
@tobias-g[1Ramp Alpha Web App] - Titles over 256 characters prevent post submission1ramp80
@fuzz-ai Steemd 0.20.6 bug - memory exhaustion when parsing malicious hello_messagesteemit/steem100
@blockchainstudiobusy feed/blog/replies/follow bugs due to API no longer supportedbusy.org68
@mightypandaBusy is showing only one post repeatedly in feed and discussionsbusy.org60
@razu788Recent Post are not showing in busy.orgbusy.org0
@harry-heightzUnable to login to Knacksteem from landing page.knacksteem70
@sourovafrin[Busy] [Version: 2.5.6] Showing a post multiple time on feed and weird behaviour while scrolling on feed and postbusy.org0
@mightypandaDeleting post removes the post before actual delete is performed1ramp40
@blockchainstudio[Bug Fix - Merged and Live!] Finally, Busy can edit posts older than 7 days!busy.org77
@curtwriterApp stops and exits when I try to key in Hashtagssteepshot0

This week we had more contributions since the start of the weekly overviews than we've had in any other week. There were 10 contributions, two times higher than last week's. There were 4 new contributors, which is twice the total number of new bug hunters that we had in the last 4 weeks.

Also, for the first time in a very long while, we had a staff pick. @fuzz-ai in his testing had observed that:

A carefully crafted hello_message sent can cause steemd to attempt allocating all available memory, causing it to crash.

To exploit the bug, a malicious witness connects to a steemd instance over the network (using the peer-to-peer protocol) and participates in the encryption handshake. When sending the normal hello_message, it populates the variant_object field with an ill-formed variant object.

A fuller writeup on the bug and how it was found can be read at @fuzz-ai/a-memory-exhaustion-attack-against-the-steem-blockchain

With the staff pick included, 7 reports were scored higher than 0. @sourovafrin and @razu788's reports were scored zero for being duplicates of an existing issue. @curtwriter's report was submitted to a project outside the whitelist, hence the score - zero.

Weekly Average Score and number of Contributions

bargraph 34.png

image.png

We can see that the average score of 70.71 is approximately 13% higher than the 11 week average of 61.29. This week's average is 9.42 higher than the 11-week average and 8.21 higher than last week's average of 62.5.

Hunter Totals and Average

.


bargraph 36.png


bargraph 37.png

This week we had 4 new contributors - @fuzz-ai, @harry-heightz, @curtwriter, @razu788.

@mightypanda and @blockchainstudio submitted two reports each. Mightypanda is the top contributor with 6 finds.

7 contributors have an average reward score of 61.29 or above, over the past 11 weeks.

Reports Reviewed By Reviewer

bargraph 38.png

bargraph 39.png

The 35 contributions received by the category in the past 10 weeks were assessed by 4 reviewers. 26 of the reports were rewarded and scored higher than 0.

  • @sachincool have now reviewed 2 contributions with an average score of 40.
  • @fego have reviewed 21 contributions with an average score of 62.41.
  • @tobias-g have reviewed 10 contributions with an average score of 56.5.
  • @crokkon have reviewed 2 contributions, with an average score of 85.

Other items

In the absence of other news, the category with the help of espoem is looking forward to implementing new guidelines to replace the existing whitelist that will let contributors submit bug reports to projects outside the steem and the whitelist.

While the new guidelines are yet to be implemented, bug-hunters and open source enthusiasts looking to help open source projects, please take a look at our whitelist of projects that you can submit bug reports for:

https://docs.google.com/spreadsheets/d/1S7ayFTEy5CBMyeJvFRgq5JUjlqZxFjWAWhhrBL0GC60/edit#gid=1954068373


If you wish to have your open source projects added to our whitelist you can contact us on our help channel at our discord server. You can also leave your questions and comments below :)


Thanks

@fego

H2
H3
H4
Upload from PC
Video gallery
3 columns
2 columns
1 column
8 Comments