5167 | Why you shouldn’t share links on Facebook |
Information disclosure |
Meta / Facebook |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2016-06-09 | 2023-06-13 |
5097 | How I got your phone number through Facebook |
Logic flaw |
Meta / Facebook |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2017-02-20 | 2023-06-13 |
4984 | How I hacked hundreds of companies through their helpdesk |
Ticket Trick
Logic flaw |
GitLab
Slack
Yammer
Kayako
Zendesk |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2017-09-10 | 2023-06-13 |
4708 | This popular Facebook app publicly exposed your data for years |
Information disclosure
Authorization flaw |
Meta / Facebook
Nametests.com |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2018-06-28 | 2023-06-13 |
4286 | Abusing autoresponders and email bounces |
Information disclosure
Logic flaw |
Google
Intigriti |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2019-02-21 | 2023-06-13 |
3565 | Hundreds of internal servicedesks exposed due to COVID-19 |
Security misconfiguration |
NA |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2020-04-02 | 2023-06-13 |
1029 | “Hey Siri, follow that car!” - How traffic cameras expose your location through parking apps. |
Information disclosure
Session hijacking |
NA |
Inti De Ceukelaire (@securinti) |
Bug Bounty | 2022-09-26 | 2023-06-13 |