#responsibledisclosure — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #responsibledisclosure, aggregated by home.social.
-
Bedtime Bug Hunting at BSides Belfast 🐛
A magic-link login, one badly timed Back button and a very unexpected result.
No fancy tools—just curiosity, testing assumptions and thinking like a real user.
Thanks to everyone who came along and to the BSides Belfast team. Recording coming soon.
https://bsidesbelfast.org/schedule/
#BSidesBelfast #CyberSecurity #AppSec #MobileSecurity #ResponsibleDisclosure
-
three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.
CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.
CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.
CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.
patched in 4.14.6.
https://github.com/wazuh/wazuh/security/advisories/GHSA-3v57-hgvj-3vj2
https://github.com/wazuh/wazuh/security/advisories/GHSA-gh4h-fx78-q8xc
https://github.com/wazuh/wazuh/security/advisories/GHSA-r6f5-h662-8ffc
#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity
-
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
-
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
-
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
-
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
-
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
https://web.brid.gy/r/https://bobdahacker.com/blog/click-to-pray
-
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
https://web.brid.gy/r/https://bobdahacker.com/blog/click-to-pray
-
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
https://web.brid.gy/r/https://bobdahacker.com/blog/click-to-pray
-
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
https://web.brid.gy/r/https://bobdahacker.com/blog/click-to-pray
-
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
https://web.brid.gy/r/https://bobdahacker.com/blog/click-to-pray
-
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
-
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
-
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
-
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
-
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
-
** UPDATE **
I've taken this down for now. I'm looking into whether I need to do responsible disclosure. If you're an expert in this area, please reach out. Thanks!
** Original post **
I published part 7 of my bike blog. This one is pretty cool, in my opinion. I discover that the access controls that ASI implemented in their electronic speed controls are easily bypassed with a brute-force attack. I also philosophize a bit about the implications of that.
https://housedillon.com/blog/flash-part-seven/
#bruteForceAttack #crack #reverseEngineer #rust #ebike #ebikes
-
#cdu #cduconnect #rezo #söder #wittmann #lilithwittmann #csu #kanzlerkandidat #youtube #youtuber #zerstörungdercdu #laschet #hacker #hacking #sicherheitslücke #whitehat #responsibledisclosure #it #itsicherheit #strafanzeige #anzeige #union #digitalisierung #neuland #datenschutz #dsgvo #privatsphäre #wahlkampf #bundestagswahl #btw21 #app #cduapp #jäger #jagen #ccc #shootthemessenger #whistleblower #demokratie #politik #internet #technologie #karikatur #cartoon