Coordinated and Responsible Vulnerability Disclosure Free Bug Bounty Program 392,037 coordinated disclosures
223,651 fixed vulnerabilities
539 bug bounties with 1058 websites
10,824 researchers, 919 honor badges

Leon | Security Researcher Profile


Security researcher Leon has already helped fix 199 vulnerabilities.



Researcher reputation:  310

Real name:
Aldo Moreno

About me:
Cybersecurity enthusiast.
Bug bounty hunter.

How to contact me:
English or Spanish communication.

[email protected]

Alternative Contacts:
[email protected]

Experience in Application Security
1-3 years

Award / Bug Bounty I prefer:
Feel free to provide bug bounty.
Paypal, Amazon gift card, BTC, t-shirt, gin, stickers or any kind of swag.

Paypal: [email protected]
BTC: 33x6BpPjBiR7g5UeefGQQuZLW2BVAd3aQV

Halls of Fame:
BBC
Dell
Papercut
PejaDesign
Tu-Chemnitz
Studis-Online
Telefonica Germany

Follow me on:
Twitter

Recommendations and Acknowledgements

    23 April, 2019
     itsecop itsecop :
Thanks Geek_Pwn, for pointed out XSS vulnerabilities on our website!
Your input was very much appreciated!
    29 March, 2019
     Downnotify Marijn Otte from DownNotifier.com:
Aldo found a big security issue in our application, using a creative way to exploit it.
    17 February, 2019
     JimM97459222 Jim from GH:
Thank you for pointing out the XSS vulnerability in our site. We appreciate your work and quick response. Thank you!!
    19 December, 2018
     HIGHFLYERS_WA Tom from WADC:
Thanks a lot for making our webserver more secure! Thums up!
    10 July, 2018
     nietofarias Ignacio Nieto from Despegar:
Thanks Aldo for reporting us some XSS vulnerabilities! It was very helpful!
    25 June, 2018
     TucWebmaster Frank Richter from TU Chemnitz:
Geek_Pwn discovered XSS bugs in my site. Thanks for reporting them to us and checking our fixes, your work is appreciated!
    7 June, 2018
     uriblackman Uri from GIDEON:
Thanks Geek_Pwn for finding and alerting us to the XSS bug.
    4 June, 2018
     pejadesign Gabriele from Peja Design:
Geek_Pwn helped me discover an fix an XSS bug. Many Thanks
    2 June, 2018
     digisolid Martin de Vries from Klik-info.nl:
Geek_Pwn found an XSS bug on our website. Thanks!
    27 May, 2018
     ClementBourgoin Clément from Biblys:
Researcher helped me discover an XSS bug. Thanks!

Shows the first 10 recommendations. See all.

Please login via Twitter to add a recommendation

Honor Badges


Number of Secured Websites

10+ Websites
50+ Websites
500+ Websites
WEB SECURITY VETERAN
1000+ Websites

Advanced Security Research

WAF Bypasser
CSRF Master
30+ Reports
AppSec Logic Master
30+ Reports
Fastest Fix
Fix in 24 hours

Outstanding Achievements

Secured OBB
OBB Advocate
Improved OBB

Commitment to Remediate and Patch

Patch Master
55% Patched
Patch Guru
65% Patched
Patch Lord
75% Patched

Recommendations and Recognition

REPUTABLE
10+ Recommends
FAMOUS
25+ Recommends
GLOBALLY TRUSTED
50+ Recommends

Distinguished Blog Author

1 Post
3 Posts
5+ Posts

Research Statistics



Total reports:343
Total reports on VIP sites:39
Total patched vulnerabilities:199
Total vulnerabilities on Hold (Open Bug Bounty):2
Recommendations received:13
Active since:20.09.2017

Open Bug Bounty Certificate





No posts in blog yet


Reported Vulnerabilities

All Submissions VIP SubmissionsFeatured Submissions

Domain Reported Status Type
02.07.2019
On Hold
Cross Site Scripting
30.06.2019
On Hold
Cross Site Scripting
02.06.2019
patched
Cross Site Scripting
27.03.2019
patched
Cross Site Scripting
18.03.2019
unpatched
Cross Site Scripting
06.03.2019
patched
Cross Site Scripting
04.03.2019
patched
Cross Site Scripting
04.03.2019
patched
Cross Site Scripting
01.03.2019
patched
Improper Access Control 
27.02.2019
unpatched
Cross Site Scripting
07.02.2019
patched
Cross Site Scripting
02.02.2019
patched
Cross Site Scripting
26.01.2019
unpatched
Cross Site Scripting
26.01.2019
patched
Cross Site Scripting
25.01.2019
unpatched
Improper Access Control 
25.01.2019
unpatched
Improper Access Control 
24.01.2019
unpatched
Cross Site Scripting
19.01.2019
patched
Improper Access Control 
19.01.2019
patched
Improper Access Control 
18.01.2019
patched
Improper Access Control 

  Latest Patched

 22.07.2019 alriyadh.com
 22.07.2019 inria.fr
 22.07.2019 wzayef.com
 22.07.2019 coderanch.com
 22.07.2019 actualidadiphone.com
 22.07.2019 careerbuilder.vn
 22.07.2019 molex.com
 22.07.2019 anidb.net
 21.07.2019 panjiva.com
 20.07.2019 fonts2u.com

  Latest Blog Posts

12.06.2019 by Open Bug Bounty
Open Bug Bounty pursues a steady growth in 2019 with over 212,148 fixed vulnerabilities
27.05.2019 by fakessh
bing openredirect
20.05.2019 by fakessh
Hitachi Incident Response Team (HIRT)
11.05.2019 by MAS00712
Footprinting and Reconnaissance with DIRB Tool (For Security Researcher and Bug Bounty Hunters)
01.05.2019 by Renzi25031469
1000's of default passwords on http://open-sez.me

  Recent Recommendations

    22 July, 2019
     shinguz:
A big thank you to Felipe for the vulnerability report of the Cross-Site Scripting (XSS) attacks! The report was detailed enough, with a simple example, to let me quickly verify and fix the issue.
    22 July, 2019
     Zefyx:
A big thanks warbid for your finding !
    22 July, 2019
     PaulAtTheHug:
Warbid found a serious vulnerability in our site and promptly reported it. They also helped verify that our patch had fixed it.
    20 July, 2019
     IbassoI:
Thanks for the vulnerability report! The report was responsible and detailed enough to let us quickly verify and diagnose the issue, understand its impact, and fix it quickly. Ayan was reacting in lightning speed once I contacted him. He explained the issue to me very clear and provided a comprehensive amount of possible solutions. This was really great service, thanks so much!
    19 July, 2019
     nitrc_info:
Thanks for the vulnerability report! The report was responsible (private and without exploiting the vulnerability) and detailed enough to let us quickly verify and diagnose the issue, understand its impact, and fix it quickly.