Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Researcher profile
Credibility earned elsewhere: verified platform standing, vendor-confirmed credits and reviewed evidence.
What you’ve added here: reviews written, and how useful others found them.
Arbitrary file write via path traversal in -u username / -U userfile output filename
Zen Browser MAR updater ships with signature verification removed — unsigned updates accepted
How this BugScore is built
BugScore weighs signal by how hard it is to fake: HackerOne’s own percentiles, vendor-confirmed credits, and evidence a moderator checked. Writing reviews here does not move it. That is Contribution, below. It is a signal to weigh, not a warranty.
How this Contribution is built
Contribution measures citizenship on BugRater: reviews, helpful votes, breadth, and tenure. It is cheap to earn by design, and it is kept deliberately separate from BugScore so activity here can never stand in for demonstrated skill.
Programs that have publicly thanked this researcher on HackerOne, with the reputation earned in each.
GitHub security advisories crediting the verified GitHub account smoke-wolf. GitHub credits an account, not a name, so these are an exact match to a login Maliq Barnard has proved they control. There is no claim to make and nothing to dispute.
Maliq Barnard can attach a fresh, time-limited attestation of this badge to a report on any platform. It attests track record: never a legal identity, and never a guarantee.
Programs reviewed
3Reviews
As the tittle says, I had three. SSRF reports go to NASA's VPR before they were all closed as informative under P5. Which, while unfortunate, had the reports triaged in under 2 days. Which is always a quality I as a research greatly appreciate from programs and vendors.
I have spent the last 4 months interacting with the Apple security response team (SRT). They have been incredibly thorough with their evaluations, informative closes are almost always accompanied by a detailed explanation as to why it is not applicable. They are fast with triage and will usually move on your report within 48 hours. The surface however, is increasingly hardened as automated security research has massively accelerated the speed at which it used to take. As such, the most critical note when submitting to Apple, always, and I mean always, prove the impact, weaponize the exploit, demonstrate the chain. If any part reads as theoretical, it will not strengthen the case for the report.
Triage overall left me relatively disappointed, but by equal measures, relived. I reported a remote code execution to this program in May, the H1 analyst team reviewed and downgraded the severity from critical to high on account of double-counting the UI:R component, in the CVSS. Two weeks after the report was closed as informative quote: "The team has confirmed that the current behavior is working as expected given the trust model of the application." After thorough, and repeated follow up and technical rebuttal the company corrected their initial decision and awarded a bounty payout. The timeline on this report was May 23 → July 9, a whole 47 days, with 27 of those days, it sitting as Informative. Ultimately their turnaround and decision to award the bounty was appreciated and I will continue to engage with them where appropriate. However, to any new researchers on H1, do not pursue this program before you have the signal to request mediation, as without it, you will be entirely at the mercy of the program.