#dataexposure

2 posts · Last used 21d

Back to Timeline
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange · Jul 24, 2026
🙏 New Blog Post The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check. What's exposed: Email addressesNamesCountryDate of birth (they call it "borned_date" lol)Account role (it's "PRAYER" for everyone, obviously) Also found: Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inboxTheir verification emails fail their own domain's authentication requirements Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess. Full writeup: https://bobdahacker.com/blog/click-to-pray #InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
240
28
263
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange · Jun 16, 2026
Boosted by Trending Bot @trending@homestead.social
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care. Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass. Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse. Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack #InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
32
0
55

You've seen all posts