Justin Gardner
6K posts

Justin Gardner
@Rhynorater
Christian | Full-time Bug Bounty Hunter | Host of @ctbbpodcast | Advisor @CaidoIO | 4x LHE MVH | 🗣️ English, 日本語 | ♥️ @mariahchan_ ♥️




if you've ever used Reframe to get sober, your private journals, your craving logs, what triggered you, how bad it got, your name, your email, all of it is sitting in a database that anyone can read without logging in i unzipped the app and found a database key in a config file. thats it. thats all it took 357,939 users exposed. disclosed april 7, no response

Update on this. ClickUp paid out max bounty on both the Split.io and SSRF findings plus a welcome bonus, $5K total. Their CEO Zeb and CISO Chris reached out to me directly after the initial disclosure, took full ownership of the issues, and now we're working together going forward on their security. Most companies ghost you or close your reports as duplicates. ClickUp actually picked up the phone. Respect to them for doing this the right way.








The best career move I ever made was abandoning traditional employment and doing my own thing! The "safe" path is not that safe in the long run!

Our biggest breakthrough in efficiency yet, the Framework Laptop 13 Pro with 20 hours of battery life. In Graphite. Linux-first with options for Ubuntu pre-installed. Featuring Intel® Core™ Ultra Series 3 processors, LPCAMM2 Memory, a new haptic touchpad, and a touchscreen display. Pre-orders for the Framework Laptop 13 Pro open now: frame.work








Live hacking season just dropped. Who’s ready? #TogetherWeHitHarder





