#clicktopray — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #clicktopray, aggregated by home.social.
-
@percepticon @clemensg Die offizielle Gebets-App des Papstes (Click to Pray) soll monatelang die Daten von rund 720.000 Nutzer:innen preisgegeben haben: Namen, E-Mail-Adressen und Herkunftsland waren laut Sicherheitsforscher über eine simple Schwachstelle (IDOR) abrufbar. Besonders brisant: Der Fehler wurde bereits Anfang Januar gemeldet – eine Reaktion blieb offenbar aus, und die Lücke war bei Veröffentlichung des Berichts noch offen. Bereits 2019 war die App wegen gravierender Sicherheitsmängel aufgefallen. Sensible Anwendungen brauchen Sicherheitsprüfungen – nicht nur gute Absichten.
#Datenschutz #ITSecurity #Cybersecurity #Papst #ClickToPray #AppSecurity #IDOR
-
@percepticon @clemensg Die offizielle Gebets-App des Papstes (Click to Pray) soll monatelang die Daten von rund 720.000 Nutzer:innen preisgegeben haben: Namen, E-Mail-Adressen und Herkunftsland waren laut Sicherheitsforscher über eine simple Schwachstelle (IDOR) abrufbar. Besonders brisant: Der Fehler wurde bereits Anfang Januar gemeldet – eine Reaktion blieb offenbar aus, und die Lücke war bei Veröffentlichung des Berichts noch offen. Bereits 2019 war die App wegen gravierender Sicherheitsmängel aufgefallen. Sensible Anwendungen brauchen Sicherheitsprüfungen – nicht nur gute Absichten.
#Datenschutz #ITSecurity #Cybersecurity #Papst #ClickToPray #AppSecurity #IDOR
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity