Back to Labs HackerOne #1549206 — Reddit — $5,000 Bounty
47.3k
What's something that's technically legal but feels morally wrong?
1838 Comments Share Save
Sort by: Top Best New Hot
34.2k
u/VelvetThunder_x 34.2k points 13h
Replying to a "read" message hours later and pretending you just saw it. We all know. We all do it. Nobody talks about it.
28.7k
u/QuantumFogg 28.7k points 13h
Using the self-checkout lane with a full cart because there's no sign saying you can't.
19.1k
u/NeonSerpent42 19.1k points 12h
Loud phone calls in public places. Not illegal, but the social contract clearly says this is wrong.
14.8k
u/MirrorBreaker 14.8k points 11h
Subscribing someone to a mailing list using their email. Technically legal, definitely annoying.
11.2k
u/CopperVault99 11.2k points 10h
Returning something to a store after clearly using it. The policy allows it. Your conscience shouldn't.
8.9k
u/SilverOrbit_7 8.9k points 9h
Asking for a raise by referencing a competing job offer you never actually applied for.

Real World Lab — What to Find

This page simulates Reddit's Shreddit API comments endpoint.
Access it using the real URL path pattern:

/59.php/svc/shreddit/api/comments/askreddit/POST_ID/t1_COMMENT_ID

The POST_ID path segment is reflected raw in an unquoted id attribute on the "See More Comments" button at the bottom of this page. Unlike Labs 56–58, there are no quotes to break out of — a single space character (%20) is enough to inject a new attribute.

The XSS fires on mouseover — hover over the button after injecting.

Payload: t3_u9po1l%20onmouseover=alert(document.domain)%20y=

Platform: HackerOne
Report: #1549206
Target: sh.reddit.com
Severity: High (7–8.9)
Bounty: $5,000
Researcher: abhiramsita
Status: Resolved (May 2022)