home.social

#responsibledisclosure — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #responsibledisclosure, aggregated by home.social.

  1. 🐱 New Blog Post: Petlibro Smart Pet Feeder Vulnerabilities (Partially Fixed, $500)

    Found critical vulns in Petlibro - one of the biggest smart pet feeder companies:

    • Auth bypass via broken OAuth - just need Google ID (public info via Google APIs) to login as anyone
    • Access any pet's data, devices, serial numbers, MAC addresses
    • Hijack any device - change feeding schedules, access cameras
    • Access private audio recordings (mealtime messages to pets)
    • Add yourself as shared owner to any device

    The worst part? They "fixed" the auth bypass by making a new endpoint... but left the old vulnerable one active for "legacy compatibility." Two months later, still working.

    Also tried to get me to sign an NDA AFTER paying the bounty. That's not how contracts work.

    Full writeup: bobdahacker.com/blog/petlibro

    #InfoSec #BugBounty #ResponsibleDisclosure #IoT #Petlibro #Security #Privacy #CyberSecurity #SmartHome #OAuth

  2. In August 2020, @SchizoDuckie and I published what was to become the first of a series of articles or posts called "No Need to Hack When It's Leaking."

    In today's installment, I bring you "No Need to Hack When It's Leaking: Brandt Kettwick Defense Edition." It chronicles efforts by @JayeLTee, @masek, and I to alert a Minnesota law firm to lock down their exposed files, some of which were quite sensitive.

    Read the post and see how even the state's Bureau of Criminal Apprehension had trouble getting this law firm to respond appropriately.

    databreaches.net/2025/07/04/no

    Great thanks to the Minnesota Bureau of Criminal Apprehension for their help on this one, and to @TonyYarusso and @bkoehn for their efforts.

    #dataleak #misconfiguration #incidentresponse #incidentmanagement #responsibledisclosure #securityalert #infosec