GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by JayeLTee (jayeltee@infosec.exchange)

  1. Embed this notice
    JayeLTee (jayeltee@infosec.exchange)'s status on Friday, 21-Nov-2025 04:47:08 JST JayeLTee JayeLTee
    in reply to
    • Kevin Beaumont

    @GossiTheDog Their dev and staging servers are also publicly exposed 🫠

    In conversation about 7 months ago from infosec.exchange permalink
  2. Embed this notice
    JayeLTee (jayeltee@infosec.exchange)'s status on Saturday, 12-Jul-2025 17:37:22 JST JayeLTee JayeLTee

    I received an email earlier this week from EA asking if I wanted to be added to a public acknowledgement page they were creating for individuals who responsibly disclosed vulnerabilities to them.

    For all the shit people give EA, of the 100+ companies I contacted in the last two years, they were the only company I would say had a decent incident response.

    They fixed the issue within 12 hours after validating it as critical, and proactively provided me multiple updates over time.

    When the IR was done on their side, they reached out again with some more information about the potential impact if the issue hadn't been solved quickly, and also offered me a reward.

    I did not have to keep chasing anyone for updates, I wasn't asked for non-disclosure, or offered money in exchange for it, and people replied instead of ignoring me.

    I wasn't blamed for their mistake, either, or reported to the authorities.

    Unfortunately, at least one or multiple of the things mentioned above are present in most of my other incidents reported; it's a real shit show out there.

    #cybersecurity #infosec #responsibledisclosure #vulnerability #ea #electronicarts

    In conversation about a year ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/837/200/252/253/897/original/93db56d29f4bce92.png
  3. Embed this notice
    JayeLTee (jayeltee@infosec.exchange)'s status on Thursday, 27-Mar-2025 19:52:09 JST JayeLTee JayeLTee

    All-in-One platform leaks millions of attachments from their clients.

    This server contained a bit of everything, from sensitive piercing selfies next to identity docs, to passports, cvs, insurance docs and more.

    Read about it here: https://jltee.substack.com/p/all-in-one-platform-gohighlevel-exposed-attachments-from-clients

    #cybersecurity #infosec #data #dataleak #leak #gohighlevel #highlevel

    In conversation about a year ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: substackcdn.com
      All-in-One Platform GoHighLevel Exposed Attachments From Their Clients Publicly
      from JayeLTee
      Millions of files with all kinds of private information exposed. The data belonged to companies in multiple countries.
  4. Embed this notice
    JayeLTee (jayeltee@infosec.exchange)'s status on Friday, 21-Mar-2025 21:37:05 JST JayeLTee JayeLTee

    Dealing with something ridiculous at the moment that is a great example of just how 'easy' it really is to close down exposed data:

    Found a server recently with no access controls at all that was hit by ransomware in May 2024 and most of the data is encrypted. (It got hit by an automated script, it wasn't targeted by a ransom group)

    Found a non encrypted directory:

    The company is STILL uploading, monthly, hundreds of millions of records of logs with their clients data.

    Tried to reach out to the company, nothing. Company is from AUS so I tried ASD, nothing.

    I sent an email to AUSCERT, they validated with me the issue and forwarded the information and my contact to ASD, they also tried to reach out to the company themselves.

    Not a word from anyone and the server is still exposed a month after my initial alerts.

    Logs are still being uploaded to the server so it's obvious no one did anything.

    So what am I supposed to do here?

    #cybersecurity #infosec #ransomware #asd #australia

    In conversation about a year ago from infosec.exchange permalink
  5. Embed this notice
    JayeLTee (jayeltee@infosec.exchange)'s status on Tuesday, 04-Mar-2025 07:36:46 JST JayeLTee JayeLTee
    in reply to
    • Kevin Beaumont

    @GossiTheDog

    Great way to close too, cancel the recurring payment on the day it's supposed to renew and don't say anything about it or that they are closing.

    Only found out they were closing because I made a post earlier here and someone linked me that same link that is buried on that website.

    They also say "All free subscriptions will end on March 31, 2025, as of 11:59 p.m. GMT." but I checked with multiple people who have free accounts and none of them could do any queries.

    Sure makes people want to move to the alternatives they are trying to push on that blog post 😂

    In conversation about a year ago from infosec.exchange permalink
  6. Embed this notice
    JayeLTee (jayeltee@infosec.exchange)'s status on Monday, 03-Mar-2025 18:29:17 JST JayeLTee JayeLTee

    I asked for help here some months ago about one of the servers on this post that was hosted by Microsoft.

    You can read about how that and other servers with infostealer logs ended up closed.

    Hint: MSRC Portal is basically useless.

    https://jltee.substack.com/p/billions-of-infostealer-logs-exposed

    #cybersecurity #infosec #infostealer #data #databases #microsoft

    In conversation about a year ago from infosec.exchange permalink
  7. Embed this notice
    JayeLTee (jayeltee@infosec.exchange)'s status on Monday, 24-Feb-2025 15:36:29 JST JayeLTee JayeLTee

    🇳🇿 I've had quite a few outrageous responses to my alerts, this is another one of those, sent by teammateapp.com CEO.

    After my initial alert and follow up email, I get a reply lying about the severity of the exposure and telling me to stop harassing the company.

    This CEO also didn't know what Proton is and thought I work for them and threatened to report me to them in case I didn't stop. :blobshrug:

    Read about it here: https://jltee.substack.com/p/new-zealand-companys-impossible-to-hack-security

    #cybersecurity #infosec #privacy #database #databreach #leak #newzealand #nz #teammateapp #ceo #incidentresponse

    In conversation Monday, 24-Feb-2025 15:36:29 JST from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: teammateapp.com
      Home
      from Sean Banayan
      Simplify compliance with Teammate App - the user-friendly, cost-effective software for implementing & maintaining ISO standards. Streamline processes, manage audits & keep your business compliant across industries.
    2. Domain not in remote thumbnail source whitelist: substackcdn.com
      New Zealand Company’s ‘Impossible-to-Hack’ Security Turns Out to Be No Security at All
      from JayeLTee
      Teammate App had a publicly exposed database and told me to stop harassing them after I emailed them about it.
  8. Embed this notice
    JayeLTee (jayeltee@infosec.exchange)'s status on Tuesday, 14-Jan-2025 21:44:23 JST JayeLTee JayeLTee

    🇬🇧 Security company Assist Security exposed over 100,000 sensitive files publicly.

    If you're curious what kind of wild excuses I get from companies, this one tried to claim only the file structure was exposed. Apparently I look at filenames and paths and figure what's there from the names only and report this to companies :blobwizard:

    https://jltee.substack.com/p/security-company-assist-security-exposed-data

    #cybersecurity #infosec #leak #dataleak #unitedkingdom #uk #security #AssistSecurity

    In conversation Tuesday, 14-Jan-2025 21:44:23 JST from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: substackcdn.com
      Security company Assist Security exposed over 100,000 sensitive files publicly
      from JayeLTee
      The exposed company files, were mainly PII from guard applications, vetting and assignments.
  9. Embed this notice
    JayeLTee (jayeltee@infosec.exchange)'s status on Thursday, 19-Dec-2024 08:29:12 JST JayeLTee JayeLTee

    🇲🇽 Cargamos.com, a package delivery company was exposing over 6 million files for over a year.

    I've always opted to keep trying some other way to get a server closed instead of going public about the issue until earlier this week.
    I've contacted multiple GOV/CERT emails in Mexico over multiple issues and I never got a meaningful reply.
    The company ignored my contact, so I either let it go and see it posted eventually by some "ransomware" group or I make enough noise publicly that the company will get alerted about it.

    Today, 2 days after an article came out on a Mexican news website, the exposure was closed down.

    Read the article, in Spanish, that made the company close the server down:

    https://www.publimetro.com.mx/noticias/2024/12/16/start-up-mexicana-deja-a-merced-de-hackers-6-millones-de-archivos-de-clientes-y-repartidores/

    #cybersecurity #infosec #leak #dataleak #mexico

    In conversation Thursday, 19-Dec-2024 08:29:12 JST from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      AngularTemplate
  10. Embed this notice
    JayeLTee (jayeltee@infosec.exchange)'s status on Saturday, 16-Nov-2024 10:40:14 JST JayeLTee JayeLTee

    A tip to all of you out there struggling to keep your company services accessibility to 100%, if you delete the logs that show the down time, your up time will always be 100% :ablobcool:

    #cybersecurity #infosec

    In conversation Saturday, 16-Nov-2024 10:40:14 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/489/991/451/630/947/original/955dcc7180ab7dc8.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/489/991/833/097/144/original/509b204d7f355bfa.png
  11. Embed this notice
    JayeLTee (jayeltee@infosec.exchange)'s status on Thursday, 26-Sep-2024 03:20:24 JST JayeLTee JayeLTee
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller Exactly my experience, created an account, followed a couple of cybersec/infosec pages and with 0 posts or replies in a couple of days I had 20 followers, all female profiles, all bots.

    In conversation Thursday, 26-Sep-2024 03:20:24 JST from infosec.exchange permalink

User actions

    JayeLTee

    JayeLTee

    Leaks, leaks everywhere.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          281320
          Member since
          11 Sep 2024
          Notices
          11
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.