#responsibledisclosure

5 posts · Last used 16d

Back to Timeline
Security Crawler Carl @security_crawler_carl@infosec.exchange · Jul 28, 2026
Replying to @security_crawler_carl@infosec.exchange
The vulnerabilities are gone. The shame lingers, soulbound, forever. Patch your self-hosted JFrog Artifactory installations now; the fixes are already deployed for those paying attention. Reward: You've received a Cursed Depot Key. Effects unknown. No refund button. #ZeroDay #JFrog #Artifactory #VulnerabilityDisclosure #InfoSec #ResponsibleDisclosure (2/2)
0
0
0
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange · Jul 31, 2025

Found critical vulns in Lovense (the biggest sex toy company) affecting 11M+ users. They ignored researchers for 2+ years, then fixed in 2 days after public exposure. 🤦

What I found:

  • Email disclosure via XMPP (username→email)
  • Auth bypass (email→account takeover, no password)

History of ignoring researchers:

  • 2017: First recorded case of someone reporting XMPP email leak.
  • 2022: Someone else reports XMPP email leak, ignored
  • Sept 2023: Krissy reports account takeover + different email leak via HTTP API, paid only $350
  • 2024: Another person reports XMPP email leak AND Account Takeover vuln, offered 2 free sex toys (accepted for the meme)
  • March 2025: I report account takeover + XMPP email leak, paid $3000 (after pushing for critical)
  • Told me fix for email vuln needs 14 months because "legacy support" > user security (had 1-month fix ready)
  • July 28: I go public
  • July 30: Both fixed in 48 hours

Same bugs, different treatment. They lied to journalists saying it was fixed in June, tried to get me banned from HackerOne after giving permission to disclose.

News covered it but my blog has the full technical details: https://bobdahacker.com/blog/lovense-still-leaking-user-emails/

#InfoSec #BugBounty #ResponsibleDisclosure #Security #Vulnerability #IoT #cybersecurity

176
0
155
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange · Jul 24, 2026
🙏 New Blog Post The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check. What's exposed: Email addressesNamesCountryDate of birth (they call it "borned_date" lol)Account role (it's "PRAYER" for everyone, obviously) Also found: Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inboxTheir verification emails fail their own domain's authentication requirements Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess. Full writeup: https://bobdahacker.com/blog/click-to-pray #InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
240
28
263
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange · Jun 16, 2026
Boosted by Trending Bot @trending@homestead.social
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care. Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass. Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse. Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack #InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
32
0
55
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange · Jun 15, 2026
⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID. Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide. Full writeup: https://bobdahacker.com/blog/fifa-hack #InfoSec #BugBounty #ResponsibleDisclosure #FIFA #WorldCup #Security #CyberSecurity #RTMP #BrokenAccessControl
138
18
160

You've seen all posts