#responsibledisclosure — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #responsibledisclosure, aggregated by home.social.
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
https://web.brid.gy/r/https://bobdahacker.com/blog/click-to-pray
-
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
https://web.brid.gy/r/https://bobdahacker.com/blog/click-to-pray
-
Oh, look! An anonymous hero 🤡 on #GitHub is handing out unreported 0-days like candy, because nothing screams "responsible disclosure" quite like a digital piñata of exploits. 🎉 But hey, don't abuse them, they're just for "alluring" people. Yeah, right. 🙄
https://github.com/bikini/exploitarium #anonymoushero #0days #responsibleDisclosure #cybersecurity #HackerNews #ngated -
Oh, look! An anonymous hero 🤡 on #GitHub is handing out unreported 0-days like candy, because nothing screams "responsible disclosure" quite like a digital piñata of exploits. 🎉 But hey, don't abuse them, they're just for "alluring" people. Yeah, right. 🙄
https://github.com/bikini/exploitarium #anonymoushero #0days #responsibleDisclosure #cybersecurity #HackerNews #ngated -
Fileless RCE on stock Android (~2.5B devices). Reported to Google VRP, confirmed by their own engineering team, closed as NSBC anyway.
#AndroidSecurity #infosec #Android #MobileSecurity #VulnerabilityResearch #RCE #BugBounty #VRP #ResponsibleDisclosure #AppSec #ThreatIntel #WebView #ZeroDay #CVE
-
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
-
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
-
You demonstrate a fileless RCE chain. Complex delivery, in-memory execution, zero detections, confirmed working on multiple devices.
The vendor reviews it twice, involves engineering, then tells you:
"Your research demonstrates a complex chain for delivering and executing code."
...and closes it as 'intended behavior. Not a platform vulnerability.'
Question: is it a vulnerability?
Follow-up: does your answer change if the attack surface exists *between* components — where no single owner's scope definition covers the full chain?
Asking because I have a paper dropping soon about that.
#VRP #responsibleDisclosure #semanticGap #infosec #securityResearch
-
⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide.
Full writeup: https://bobdahacker.com/blog/fifa-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FIFA #WorldCup #Security #CyberSecurity #RTMP #BrokenAccessControl
-
⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide.
Full writeup: https://bobdahacker.com/blog/fifa-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FIFA #WorldCup #Security #CyberSecurity #RTMP #BrokenAccessControl
-
https://deadeclipse666.blogspot.com/2026/03/
Yeah, well, presumably Microsoft corporation or someone who works at it is the one who did that to you, not all users of affected Microsoft products. So shut the fuck up.
I fucking hate people who punish or blame innocents in their blind rage.#ethics #cybersecurity #responsibledisclosure #NightmareEclipse #Microsoft #Windows
-
Auf der @gulasch in Karlsruhe haben wir gemeinsam mit der @informatik und @Anoxinon einen Workshop zum #Computerstrafrecht und dem sogenannten #Hackerparagraph gehalten. Jeder Stuhl im Raum war besetzt, die Warteliste lang.
Das freut uns; zeigt aber vor allem, wie groß der Gesprächsbedarf beim Thema #ResponsibleDisclosure ist.
➡️https://load-ev.de/2026/06/11/gpn24-rueckblick/
Foto: @ieke und @carlamelee auf der #GPN24
-
Auf der @gulasch in Karlsruhe haben wir gemeinsam mit der @informatik und @Anoxinon einen Workshop zum #Computerstrafrecht und dem sogenannten #Hackerparagraph gehalten. Jeder Stuhl im Raum war besetzt, die Warteliste lang.
Das freut uns; zeigt aber vor allem, wie groß der Gesprächsbedarf beim Thema #ResponsibleDisclosure ist.
➡️https://load-ev.de/2026/06/11/gpn24-rueckblick/
Foto: @ieke und @carlamelee auf der #GPN24
-
Microsoft Revives Vulnerability Disclosure Debate with Researcher Crackdown
Microsoft is stirring up controversy in the vulnerability disclosure debate, clashing with a security researcher over the responsible handling of zero-day vulnerabilities. The tech giant's strong response, including threats of legal action, has sparked heated discussion on coordinated disclosure.
#VulnerabilityDisclosure #CoordinatedDisclosure #ZeroDay #Microsoft #ResponsibleDisclosure
-
California Back & Pain Specialists exposed 133GB of patient PHI on a public server (3,400+ driver’s licenses + full medical records).
After responsible disclosure, AWS took it offline. Company remains silent.
#DataBreach #CyberSecurity #HIPAA #ResponsibleDisclosure #Healthcare
Full report
https://write-ups.security-chu.com/2026/06/California-Back-Pain-Specialists-with-data-breach.html
-
California Back & Pain Specialists exposed 133GB of patient PHI on a public server (3,400+ driver’s licenses + full medical records).
After responsible disclosure, AWS took it offline. Company remains silent.
#DataBreach #CyberSecurity #HIPAA #ResponsibleDisclosure #Healthcare
Full report
https://write-ups.security-chu.com/2026/06/California-Back-Pain-Specialists-with-data-breach.html
-
AI-Powered Vulnerability Disclosure Forces Urgent Remediation Push
The era of reactive vulnerability disclosure is over - it's time for a coordinated, global effort to stay ahead of AI-powered threats, involving governments, software vendors, and emergency responders. With AI now capable of identifying exploitable vulnerabilities at unprecedented…
#AipoweredVulnerabilityDisclosure #ResponsibleDisclosure #ArtificialIntelligence #VulnerabilityManagement #EmergingThreats
-
#Microsoft walks back its threat to pursue those who don't disclose responsibly as criminals. They don't apologize, but merely "clarify" their position in a post on X.com today. Since their statement doesn't seem to be on their blog, I am linking to x.com:
https://x.com/msftsecresponse/status/2061293718942908925
This is the type of threat to researchers that @zackwhittaker and I had been looking at in our survey on threats to journalists and researchers. It was impressive to see all of the experts like @GossiTheDog speaking up to slam Microsoft for their blog post of May 27.
Confronted with overwhelming criticism by the security community, Microsoft stepped back.
-
#Microsoft walks back its threat to pursue those who don't disclose responsibly as criminals. They don't apologize, but merely "clarify" their position in a post on X.com today. Since their statement doesn't seem to be on their blog, I am linking to x.com:
https://x.com/msftsecresponse/status/2061293718942908925
This is the type of threat to researchers that @zackwhittaker and I had been looking at in our survey on threats to journalists and researchers. It was impressive to see all of the experts like @GossiTheDog speaking up to slam Microsoft for their blog post of May 27.
Confronted with overwhelming criticism by the security community, Microsoft stepped back.
-
Security.txt is a relatively new standard that helps security reseachers report vulnerabilities in your website or IT systems. This makes the internet more secure for everyone.
@SIDN has published a new information page in English on security.txt: https://www.sidn.nl/en/modern-internet-standards/security-txt
Want to know if security.txt is set up correctly on your website? Test it on https://Internet.nl!
#securitytxt #security #responsibledisclosure #internetstandards
-
Security.txt is a relatively new standard that helps security reseachers report vulnerabilities in your website or IT systems. This makes the internet more secure for everyone.
@SIDN has published a new information page in English on security.txt: https://www.sidn.nl/en/modern-internet-standards/security-txt
Want to know if security.txt is set up correctly on your website? Test it on https://Internet.nl!
#securitytxt #security #responsibledisclosure #internetstandards
-
Microsoft Decries Uncoordinated Zero-Day Disclosures
Microsoft slammed researchers who publicly revealed six zero-day vulnerabilities without giving the company a heads-up, putting customers at unnecessary risk. The tech giant named and shamed the flaws, including privilege escalation vulnerabilities in Microsoft Defender and a security feature bypass vulnerability in Windows…
#ZeroDay #VulnerabilityDisclosures #Microsoft #ResponsibleDisclosure #PrivilegeEscalation
-
Sometimes I’ve found myself banging my head against the keyboard trying to contact companies to help them fix their misconfigurations and exposed servers.
After several frustrating experiences, I decided to create my own clear and structured Responsible Disclosure methodology.
Today I’m sharing it with you 👇
This flow represents how I handle vulnerabilities — always prioritizing ethical contact, escalation when necessary, and only publishing write-ups once the issue is fixed.
Opinions and constructive feedback are more than welcome. Have you faced similar situations? What’s your approach?
-
Sometimes I’ve found myself banging my head against the keyboard trying to contact companies to help them fix their misconfigurations and exposed servers.
After several frustrating experiences, I decided to create my own clear and structured Responsible Disclosure methodology.
Today I’m sharing it with you 👇
This flow represents how I handle vulnerabilities — always prioritizing ethical contact, escalation when necessary, and only publishing write-ups once the issue is fixed.
Opinions and constructive feedback are more than welcome. Have you faced similar situations? What’s your approach?
-
@wdormann Of course Microsoft used their GitHub ownership to remove the repo instead of fixing both problems (the exploit and the video requirement).
-
@wdormann Of course Microsoft used their GitHub ownership to remove the repo instead of fixing both problems (the exploit and the video requirement).
-
Companies will put up all kinds obstacles to responsible disclosure for researchers to get around to make their own lives easier. But they often forget that in the end it is researcher who calls the shots. It is the researchers vuln and they can do whatever they want with it.
#vulnerability #disclosure #responsibledisclosure #windows #microsoft
-
Companies will put up all kinds obstacles to responsible disclosure for researchers to get around to make their own lives easier. But they often forget that in the end it is researcher who calls the shots. It is the researchers vuln and they can do whatever they want with it.
#vulnerability #disclosure #responsibledisclosure #windows #microsoft
-
RE: https://mastodon.nl/@SIDN/116317873852576082
Security.txt is een relatief nieuwe standaard, die beveiligingsonderzoekers helpt om kwetsbaarheden te melden. Dit draagt bij aan een veiliger internet.
@SIDN heeft haar informatiepagina over deze standaard bijgewerkt: https://www.sidn.nl/moderne-internetstandaarden/security-txt Binnenkort verschijnt ook een Engelse vertaling.
Wil je weten of security.txt op jouw website correct is ingesteld? Test het op https://Internet.nl!
#securitytxt #internetstandards #security #responsibledisclosure
-
RE: https://mastodon.nl/@SIDN/116317873852576082
Security.txt is een relatief nieuwe standaard, die beveiligingsonderzoekers helpt om kwetsbaarheden te melden. Dit draagt bij aan een veiliger internet.
@SIDN heeft haar informatiepagina over deze standaard bijgewerkt: https://www.sidn.nl/moderne-internetstandaarden/security-txt Binnenkort verschijnt ook een Engelse vertaling.
Wil je weten of security.txt op jouw website correct is ingesteld? Test het op https://Internet.nl!
#securitytxt #internetstandards #security #responsibledisclosure
-
How not to do #ResponsibleDisclosure in a nut shell:
-
How not to do #ResponsibleDisclosure in a nut shell:
-
We don't need to hack your AI Agent to hack your AI Agent …and we don't need an AI agent for that either :)
Via a large enterprise's AI assistant, we obtained access to several million Entra identities and all chat logs including attachments — no prompt injection or model tricks required.
For all we know, the poor agent was not at fault and may not have even been able to witness what was happening.
https://srlabs.de/blog/hacking-ai-agent
#AI #AIhacking #VulnerabilityDisclosure #ResponsibleDisclosure
-
We don't need to hack your AI Agent to hack your AI Agent …and we don't need an AI agent for that either :)
Via a large enterprise's AI assistant, we obtained access to several million Entra identities and all chat logs including attachments — no prompt injection or model tricks required.
For all we know, the poor agent was not at fault and may not have even been able to witness what was happening.
https://srlabs.de/blog/hacking-ai-agent
#AI #AIhacking #VulnerabilityDisclosure #ResponsibleDisclosure
-
Responsible Disclosure: o que fazer quando você acha um zero-day
Você sabe o que é responsible disclosure e por que ele é ESSENCIAL contra zero-days? 👇
• O que é:
- Responsible disclosure (divulgação responsável) = agir com ética: avisar a empresa antes de expor a vulnerabilidade.• Passo a passo prático:
- 1️⃣ Você encontra uma vulnerabilidade (zero-day)
- 2️⃣ Contata a empresa em privado e...#segurança #cybersecurity #ethicalhacking #responsibledisclosure #zeroday #infosec #MorningCrypto
-
🔐 Public disclosure: CVE-2025-69690 & CVE-2025-69691
Two authenticated RCE vulnerabilities in Netgate pfSense CE:CVE-2025-69690 (CVSS 8.8): Unsafe deserialization
→ root RCE via backup restore (pfSense 2.7.2)
CVE-2025-69691 (CVSS 9.9): XMLRPC exec_php
→ root RCE via default credentials (pfSense 2.8.0)Vendor notified Dec 2, 2025. Acknowledged, no patch planned.
Responsible disclosure followed throughout.Full write-up: https://github.com/privlabs/CVE-2025-69690-CVE-2025-69691
#CVE #pfSense #InfoSec #RCE #SecurityResearch
#ResponsibleDisclosure -
For researchers and those trying to disclose incidents responsibly or get help:
There is an international organization called FIRST.
From the FIRST Teams website:
"This is a list of the contact information for incident response teams participating in FIRST, the Forum of Incident Response and Security Teams. The teams are responsible for providing FIRST with their latest contact information for this page. The list is alphabetized by team name. All telephone numbers are preceded with the appropriate country code."
There are 829 teams listed. Some are government CERT teams, some are corporate incident response teams.
You might want to bookmark the site to speed up your attempt to contact these teams:
-
For researchers and those trying to disclose incidents responsibly or get help:
There is an international organization called FIRST.
From the FIRST Teams website:
"This is a list of the contact information for incident response teams participating in FIRST, the Forum of Incident Response and Security Teams. The teams are responsible for providing FIRST with their latest contact information for this page. The list is alphabetized by team name. All telephone numbers are preceded with the appropriate country code."
There are 829 teams listed. Some are government CERT teams, some are corporate incident response teams.
You might want to bookmark the site to speed up your attempt to contact these teams:
-
I once talked about bug bounty platforms and warned the community about them.
There are deeper issues with these platforms:
Platforms are paid by vendors, so they listen to vendors. A lot of these vendors abuse the platform to silence offensive researchers and the platforms don't care.
➡️ My recommendation remains ⬅️
- contact vendors directly via email
- use your national CERT for escalations
If you're in Europe: you're in luck, from 2027 the Cyber Resilience Act (CRA) will make it mandatory to have a responsible disclosure process, so European vendors have to answer to the national CERT (or get fined).
#PenerationTesting #pentesting #responsibledisclosure #infosec #cybersecurity #CRA #CyberResilienceAct
-
I once talked about bug bounty platforms and warned the community about them.
There are deeper issues with these platforms:
Platforms are paid by vendors, so they listen to vendors. A lot of these vendors abuse the platform to silence offensive researchers and the platforms don't care.
➡️ My recommendation remains ⬅️
- contact vendors directly via email
- use your national CERT for escalations
If you're in Europe: you're in luck, from 2027 the Cyber Resilience Act (CRA) will make it mandatory to have a responsible disclosure process, so European vendors have to answer to the national CERT (or get fined).
#PenerationTesting #pentesting #responsibledisclosure #infosec #cybersecurity #CRA #CyberResilienceAct
-
🇧🇩 Today I'm going to talk about Bondstein Technologies Limited, a company based in Dhaka, Bangladesh. One of their servers was found to be completely open and unprotected.
Bondstein Technologies Limited is a Dhaka-based technology company specializing in Internet of Things (IoT) solutions and frontier technologies. Founded in 2014, it has established itself as a leading player in Bangladesh for vehicle tracking, industrial automation, and smart connectivity.
What data was exposed?
On December 26, 2025, I discovered that the server was exposing a 22 GB SQL backup file. According to the file timestamps and metadata, this backup appears to have been publicly accessible since at least July 2025.Among the files in the backup was users.sql, which contained the following sensitive fields:
username, customer_name, First_name, Last_name, Phone_number, Additional_contact-number, email, password.
*I was able to confirm that some of the employee names were real.
Additional findings:
The exposed server's IP resolved to a properly certified HTTPS server using a subdomain under .bondstein.net. The same IP also hosted a login portal (which I did not attempt to access).With this information, we were able to accurately identify the owner and submit a responsible disclosure.
Notification:
All of this was detailed in the email I sent to several Bondstein employees on December 26, 2025. When I checked again on January 5, 2026, the exposure had been fully closed. I followed up via email to inquire about any possible reward. On January 6, they replied with the following message:
Hi Chum1ng0,
Thank you for your responsible and detailed disclosure regarding the open directory issue on our server. We sincerely appreciate you taking the time and effort to notify us of this vulnerability, which allowed us to address it quickly. Your commitment to ethical research is truly valued. We want to confirm that the issue has been fixed and access has been restricted. We would also like to clarify that the server you identified is a staging server kept for internal purposes, and not a production environment. Regarding your request for a reward, we currently do not have an official bug bounty program in place. However, we are grateful for your help in securing our infrastructure.
We appreciate your patience and look forward to potentially collaborating in the future should we establish a formal program.
Sincerely
Bondstein-NOT REWARD-
#VDP #responsibleDisclosure #misconfigurations #Bangladesh #cybersecurity #bondstein
-
🆕 blog! “Responsible Disclosure: Chimoney Android App and KYCaid”
Chimoney is a new "multi-currency wallet" provider. Based out of Canada, it allows users to send money to and from a variety of currencies. It also supports the new Interledger protocol for WebMonetization.
But it has a security flaw which cannot be ignored.
👀 Read more: https://shkspr.mobi/blog/2026/01/responsible-disclosure-chimoney-android-app-and-kycaid/
⸻
#android #CyberSecurity #ResponsibleDisclosure #security #WebMonetization -
Responsible Disclosure: Chimoney Android App and KYCaid
https://shkspr.mobi/blog/2026/01/responsible-disclosure-chimoney-android-app-and-kycaid/Chimoney is a new "multi-currency wallet" provider. Based out of Canada, it allows users to send money to and from a variety of currencies. It also supports the new Interledger protocol for WebMonetization.
It is, as far as I can tell, unregulated by any financial institution. Nevertheless, it performs a "Know Your Customer" (KYC) check on all new account in order to prevent fraud. To do this, it uses the Ukranian KYCaid platform.
So far, so standard. But there's a small problem with how they both integrate.
I installed Chimoney's Android app and attempted to go through KYCaid's verification process. For some reason it hit me with this error message.
Well, I'd better click that email and report the problem.
Oh, that's odd. What happens if I click the protected link?
Huh! I guess I've been taken to Cloudflare's website. What happens if I click on the links on their page?
Looks like I can now visit any site on the web. If Cloudflare has a link to it, I can go there. For example, GitHub.
Why is this a problem?
One of the most important things to do when testing WebViews is to make sure that only trusted content can be loaded in it. Any newly loaded page could be potentially malicious, try to exploit any WebView bindings or try to phish the user. Unless you're developing a browser app, usually you'd like to restrict the pages being loaded to the domain of your app. A good practice is to prevent the user from even having the chance to input any URLs inside WebViews (which is the default on Android) nor navigate outside the trusted domains. Even when navigating on trusted domains there's still the risk that the user might encounter and click on other links to untrustworthy content
Emphasis added
A company's app is its sacred space. It shouldn't let anyone penetrate its inner sanctum because it has no control over what that 3rd party shows its customers.
There's nothing stopping an external service displaying a message like "To continue, please transfer 0.1 Bitcon to …"
(Of course, if your KYC provider - or their CDN - decides to turn evil then you probably have bigger problems!)
There are some other problems. It has long been known that people can use in-app browsers to circumvent restrictions. Some in-app browsers have insecure configurations which can be used for exploits. These sorts of "accidentally open" browsers are often considered to be a security vulnerability.
The Fix
Ideally, an Android app like this wouldn't use a web view. It should use a KYC provider's API rather than giving them wholesale control of the user experience.
But, suppose you do need a webview. What's the recommendation?
Boring old URl validation using Android's
shouldOverrideUrlLoading()method.Essentially, your app restricts what can be seen in the webview and rejects anything else.
Risk
Look, this is pretty low risk. A user would have to take several deliberate steps to find themselves in a place of danger.
Ultimately, it is "Code Smell" - part of the app is giving off a noxious whiff. That's something you cannot afford to have on a money transfer app. If this simple security fix wasn't implemented, what other horrors are lurking in the source code?
Contacting the company
There was no security.txt contact - nor anything on their website about reporting security bugs. I reached out to the CEO by email, but didn't hear back.
In desperation, I went on to Discord and asked in their support channel for help.
Unfortunately, that email address didn't exist.
I also tried contacting KYCaid, but they seemed unable or unwilling to help - and redirected me back to Chimoney.
As it has been over two month since I sent them video of this bug, I'm performing a responsible disclosure to make people aware of the problem.
#android #CyberSecurity #ResponsibleDisclosure #security #WebMonetization -
🐱 New Blog Post: Petlibro Smart Pet Feeder Vulnerabilities (Partially Fixed, $500)
Found critical vulns in Petlibro - one of the biggest smart pet feeder companies:
- Auth bypass via broken OAuth - just need Google ID (public info via Google APIs) to login as anyone
- Access any pet's data, devices, serial numbers, MAC addresses
- Hijack any device - change feeding schedules, access cameras
- Access private audio recordings (mealtime messages to pets)
- Add yourself as shared owner to any device
The worst part? They "fixed" the auth bypass by making a new endpoint... but left the old vulnerable one active for "legacy compatibility." Two months later, still working.
Also tried to get me to sign an NDA AFTER paying the bounty. That's not how contracts work.
Full writeup: https://bobdahacker.com/blog/petlibro
#InfoSec #BugBounty #ResponsibleDisclosure #IoT #Petlibro #Security #Privacy #CyberSecurity #SmartHome #OAuth