Coordinated and Responsible Vulnerability Disclosure Free Bug Bounty Program 289,617 coordinated disclosures
162,818 fixed vulnerabilities
231,946 websites, 17,741 VIP websites
7,709 researchers, 6,915 subscribers

Spam404 Top Security Researcher Top Security Researcher of the Month Top VIP Security Researcher of the Month | Security Researcher Profile


Security researcher Spam404 has already helped fix 15802 vulnerabilities.



Researcher reputation:  690

Real name:
Cameron

How to contact me:
You can contact me via email - [email protected]

I encourage you to contact me ASAP so we can work together to quickly protect your users! All communication will be kept private.

Alternative Contacts:
Should I not respond via email (never happened!) please reach out via Twitter - @Spam404Online

Experience in Application Security
over 5 years

Award / Bug Bounty I prefer:
An acknowledgment on my profile is enough but if you feel like treating me to something extra for my time I appreciate the following -

Bug Bounty (PayPal, Bitcoin)
Swag (T-Shirt etc)

Halls of Fame:
http://www.spam404.com/security-research.html
https://hackerone.com/spam404

Follow me on:
Twitter
LinkedIn

Recommendations and Acknowledgements | Full List:

    19 July, 2018
     OBB74286025 Security from IIR:
Thank you for locating some ancient code that we no longer needed anymore. Land mine defused!
    22 May, 2018
     aartvdwerf Aart from OI:
Thanks for letting us know about this XSS vulnerability. We appreciate the quick feedback.
    15 December, 2017
     FRPJason Jason from FrontRunner:
Cameron went through a few sites for us and identified a wide range of vulnerabilities. We really appreciated his work and will definitely stay in touch.
    1 December, 2017
     nlptimes Tom from DT:
Cameron discovered an XSS vulnerability in one of our 3rd party applications and was very helpful in bringing this to our attention, notifying the software vendor and advising what area needed to be fixed. Thank you very much!
    2 October, 2017
     amercader Adrià Mercader from Open Knowledge International:
Cameron helped identify an XSS vulnerability affecting several sites. The communication was excellent and the prompt and exhaustive details helped put a patch in place in a really short time. Much appreciated.
    23 June, 2017
     ole_morten Ole Amundsen from Paladin Software:
Cameron identified several vulnerabilities for us, making us aware and giving us the opportunity to fix. Greatly appreciated !
    11 April, 2017
     TheRealXaiin Xaiin from H1Z1DB:
Cameron alerted me to some vulnerabilities on a couple of new sites I had released, he was exceptionally polite and very professional and I was able to act before anything happened to either site. Thank you Cameron!!
    27 January, 2017
     1und1 Andreas Maurer from 1&1 Internet:
Cameron reported severals bugs on our website. He was fast, polite and professional. A great help and much appreciated.
    21 December, 2016
     TeamViewer Axel Schmidt from TeamViewer:
Cameron helped us significantly improve our services, and certainly proved to be extremely knowledgeable. We are extremely grateful to him and very much appreciate his research.
    2 November, 2016
     myvidster Marques from MyVidster:
Cameron found serval XSS exploits and was quick to respond to emails. Big thanks and keep up the wonderful work.
    18 September, 2016
     Japigiacom Franco from japigia.com:
Cameron was great! He helped me to identify and definitively fix an XSS problem on an old script. Very skilled researcher! Thanks a lot!
    8 September, 2016
     ISOatUO Jim @ISOatUO from University of Otago:
Cameron found an XSS in our site, and provided fast and accurate information to allow us to reproduce and fix. Thanks :-)
    2 September, 2016
     christopherbolt Chris from BoltMail:
Cameron reported and helped us to resolve an XSS bug with our site, he was fast, polite and professional. A great help and much appreciated.
    22 August, 2016
     traperto Thorsten Rintelen from traperto GmbH:
Cameron helped us to identify some XSS vulnerabilities on the website of some of our customers. Thank you very much!
    17 August, 2016
     mherrma50656928 Marcel Herrmann from APTIS GmbH:
Cameron helped us to identify some XSS vulnerabilities on the website of one of our customers. Thank you!
    29 June, 2016
     goathunter Hunter Goatley from Process Software:
Thanks for reporting the vulnerability. I was able to produce a fix for it easily, but it's not something I'd have ever thought to try.
    28 June, 2016
     bryandowen Bryan Owen from Medallia:
Cameron identified two issues with our web site, and shared details with us right away. He's doing this for the right reasons - and really doing a public service. Thank you, Cameron!
    6 June, 2016
     MakerGen Maker Gen from Maker Studios:
Cameron's report and subsequent description of multiple XSS vulnerabilities on our site was handled with extreme grace. The report informed us of these vulnerabilities without exposing it to third-parties. Once contacted about the issue, Cameron almost immediately got back to us with a detailed explanation of how to reproduce each of the found vulnerabilities which allowed us to fix them.
    6 June, 2016
     johngrenham John Grenham from johngrenham.com:
A great help and much appreciated
    1 June, 2016
     robferrer Rob Ferrer from Presto Classical Ltd:
Many thanks to Cameron for his swift and professional disclosure, and polite and quick responses to email. A big help.
    27 May, 2016
     odako1 Koichi Oda from odalab.org:
I appreciate Cameron's report on the XSS vulnerability of my site and his responsive and straightforward explanation about the bug. It helped us a lot. We could put my site on the safe track again. Very nice.
    26 May, 2016
     daverodenbaugh Dave from AWPCP:
Cameron reported an outdated plugin exploit from my site I had neglected to do something about--and I was able to remove it before I got hacked. Thanks, Cameron!
    24 May, 2016
     xlaunay Xavier from Daily Connect:
Thanks for identifying and reporting the vulnerability, and for making the web a safer place. Much appreciated.
    13 May, 2016
     domhnallmurphy Domhnall Murphy from ExamTime Ltd:
Cameron helped to highlight some stray DNS records that needed removal on our domain. Many thanks for that!!
    6 May, 2016
     wladekbb wladek from Wikia:
Cameron helped find and fix those issues. He showed a great combination of responsiveness and being helpful along the road. Thank you!
    5 May, 2016
     fgjordan Forrest from rewardStyle:
Cameron helped us identify and confirm a patch to a vulnerability in one of our sites. Thanks Cameron!
    5 May, 2016
     ActOnSoftware Paige Musto from Act-On Software:
Cameron's concise report allowed us to develop a fix quickly and efficiently. Thanks!
    1 May, 2016
     cpweather Christian :
Cameron was really nice, professional and responsive. It helped me to locate a vulnerability I was not aware of! Thanks so much!
    22 April, 2016
     journalclubapp Dave from Peripheral Brain, LLC:
Cameron was incredibly fast, nice, and professional. Highly recommended.

Dave
    22 April, 2016
     roygrubb Roy Grubb from InformationTamers:
My thanks to Cameron for helping keep the Web a safer place. Vuln identified and reported by Cameron with example, and now fixed.

Appreciation!
Roy
    21 April, 2016
     s_s_h_f Alex from SACD:
Thx to Dave for his warning.
The vulnerability was patched in due time.
    17 April, 2016
     EarthRef EarthRef from EarthRef:
Cameron was very helpful and responsive in helping us patch the vulnerability. Excellent job!
    15 April, 2016
     davex0x29a Dave from Purplepixie:
Thanks so much! Great help in bringing our attention and such prompt assistance to narrow down.
    13 April, 2016
     reuben_smith Reuben from wikiHow:
Thanks you for bringing these issues to our attention!
    8 April, 2016
     onWebChat PPsil. from onWebChat:
Thank you Cameron for bringing this to our attention. Very good support and really fast help!
    30 March, 2016
     MagnusJacobi Magnus from Jigidi:
Thanks to Cameron we got less vulnerabilities now.
    23 March, 2016
     Andy_GIbbons Andy Gibbons from NetSupport Ltd:
So you get a notification that your website has a security Vulnerability, and you first thought is Oh No and you might think bad of the person reporting it. Well if its spam404 nothing could be further from the truth. Spam404 was very helpful when I contacted him and very prompt with responses, the information he provided made it easy to rectify the issue quickly. I would highly recommend Spam404.
    21 March, 2016
     ozhermit Joel from N/A:
Cameron is extremely responsive and professional. His work to make the internet a safer place is exceptional.
    18 March, 2016
     jameswyeo James from SMU:
Thanks Cameron for all your help and expertise to detect XSS vulnerabilities on our sites. I contacted him after he alerted us and he provided clear instructions on the detection and re-verification. Thanks a million Spam404.
    17 March, 2016
     SteveTTech1 @stevettech1 from PR:
Thanks for bringing this to our attention. Much appreciated.
    16 March, 2016
     smu_mtam Michael from SMU:
He was very helpful in identifying the issue. Thank you!
    7 March, 2016
     fedeisas Fede from Workana:
Cameron was very helpful and provided a clear proof-of-concept to fix an XSS vulnerability in our site. Fast and courteous responses, highly recommended.
    7 March, 2016
     FamousEccles Rob from Freeola:
Thanks for bringing this to our attention. Very prompt and professional.
    6 March, 2016
     Seemorgh Admin from Seemorgh:
Spam404 provided us with clear information about vulnerabilities on our site with out any expectation, Much appreciated.
    4 March, 2016
     SeanAtStitcher Sean Simpson from Stitcher:
Cameron was very quick and courteous, and provided a simple PoC that didn't require reverse engineering to determine it wasn't malicious.
    2 March, 2016
     gregrgay Greg from ATutorSpaces:
Highly recommend Spam404. Easy to test proof of concept. Quickly helped resolve a potential vulnerability.
    1 March, 2016
     wlmthree William from Knowmad:
Kudos to Spam404 for providing a safe proof-of-concept that allowed us to track down the issue. Thanks to @xbrowsertesting for providing the tools (e.g., old browsers) to find this bug.
    29 February, 2016
     Elimontan @elimontan from Njuskalo:
Highly recommended, exceptionally responsive, precise in communication, gives good explanation with proof of concept.
    29 February, 2016
     patrick15018630 Patrick from 123RF:
Cameron was very helpful and response promptly every time we contacted each other. Effective and accurate information is given well at the start to speed up the process. Highly recommended.
    23 February, 2016
     deniak974 deniak974 from W3C:
Great feedback with useful recommendations. Much appreciated!
    18 February, 2016
     mikeraynham Mike from Flatshare:
Spam404 provided us with clear information about vulnerabilities on our site, and did so in a courteous and professional manner. Thank you.
    14 February, 2016
     mike_geogebra Michael Borcherds from GeoGebra:
Thanks, very helpful!
    14 February, 2016
     horst_no horst_no :
Very helpful! Provides proof-of-concept. Much appreciated!
    14 February, 2016
     casterln Gary from UC Berkeley:
much appreciated alert. Will take seriously any future notices for sure. Very helpful. Recommended!
    10 February, 2016
     scubacom Daniel from eScuba:
Totally recommend!! Extremely knowledgeable and responsive - pointed us exactly to the right issue.
    10 February, 2016
     jberciano Javier from CERTSI:
Very helpful information shared with us and extremely responsive.
    9 February, 2016
     ashJermaine Ashley Ross from Ensemble Group:
Very helpful providing useful information along with proof-of-concept. I highly recommend.
    7 February, 2016
     STEPHENJBERRY Steve Berry from Caregroup:
Very helpful notices; clear threat information and extremely responsive.
    2 February, 2016
     ChakraOS Hans Tovetjärn from Chakra:
Polite and precise, provides proof-of-concept. Much appreciated.
    26 January, 2016
     rkeeneybbq robsc from vetfriends.com:
Very helpful! I appreciate what you do.
    19 January, 2016
     JoeDRamsey :
Extremely helpful.. appreciate your assistance!
    14 January, 2016
     mahnamahna :
very helpful, very kind; recommended!
    10 December, 2015
     gus81 :
    9 December, 2015
     mshilman :
    3 December, 2015
     R3NW4 :
    2 December, 2015
     mikeninkranz :
    2 December, 2015
     urochestersp :
    29 November, 2015
     ret2libc :

Please login via Twitter to add a recommendation

Awards and Achievements


Number of Secured Websites

10+ Websites
50+ Websites
500+ Websites
WEB SECURITY VETERAN
1000+ Websites

Advanced Security Research

WAF Bypasser
CSRF Master
30+ Reports
AppSec Logic Master
30+ Reports
Fastest Fix
Fix in 24 hours

Outstanding Achievements

Secured OBB
OBB Advocate
Improved OBB

Commitment to Remediate and Patch

Patch Master
55% Patched
Patch Guru
65% Patched
Patch Lord
75% Patched

Recommendations and Recognition

REPUTABLE
10+ Recommends
FAMOUS
25+ Recommends
GLOBALLY TRUSTED
50+ Recommends

Research Statistics



Total reports:24487
Total reports on VIP sites:1636
Total patched vulnerabilities:15802
Total vulnerabilities on Hold (Open Bug Bounty):176
Recommendations received:68
Active since:03.11.2015
Top Security Researcher Awards: The Top Security Researcher The Top Security Researcher Top Security Researcher of the Month Top Security Researcher of the Month Top Security Researcher of the Month Top Security Researcher of the Month Top Security Researcher of the Month Top Security Researcher of the Month Top Security Researcher of the Month Top Security Researcher of the Month Top Security Researcher of the Month Top Security Researcher of the Month Top Security Researcher of the Month Top Security Researcher of the Month Top Security Researcher of the Month Top Security Researcher of the Month Top Security Researcher of the Month Top Security Researcher of the Month Top Security Researcher of the Month
Top VIP Security Researcher Awards: Top VIP Security Researcher of the Month Top VIP Security Researcher of the Month Top VIP Security Researcher of the Month Top VIP Security Researcher of the Month Top VIP Security Researcher of the Month Top VIP Security Researcher of the Month Top VIP Security Researcher of the Month Top VIP Security Researcher of the Month Top VIP Security Researcher of the Month Top VIP Security Researcher of the Month Top VIP Security Researcher of the Month Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week Top VIP Security Researcher of the Week

Open Bug Bounty Certificate



Reported Vulnerabilities

All Submissions VIP SubmissionsFeatured Submissions

Domain Reported Status Type
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting
08.11.2018
On Hold
Cross Site Scripting

  Latest Patched

      inside-handy.de
    Patched on 14.11.2018
      skidkaonline.ru
    Patched on 14.11.2018
      moat.com
    Patched on 14.11.2018
      unimi.it
    Patched on 13.11.2018
      posindonesia.co.id
    Patched on 13.11.2018
      damplips.com
    Patched on 13.11.2018
      toysrus.ca
    Patched on 13.11.2018
      alura.com.br
    Patched on 13.11.2018
      chess24.com
    Patched on 13.11.2018
      24livenewspaper.com
    Patched on 13.11.2018

  Recent Recommendations

    13 November, 2018
     ngjermundshaug:
Awesome work - you seem very skilled. Best of luck with university and career.
    13 November, 2018
     WebNet51650767:
Armin found a vulnerability on one of our websites and reported it to us. We have already fixed the vulnerability ! Many thanks
    13 November, 2018
     HoutVasthouden:
Thank you for reporting XSS issues. It's patched now.
    12 November, 2018
     kevinBaseCom:
Thank you for reporting a security issue with our website and for promptly providing the affected pages.
    12 November, 2018
     thomasgussekloo:
Thanks Thijs for reporting an open redirect bug in our website. It's fixed based on your email and information.