fakessh | Security Researcher Profile
Security researcher fakessh has already helped fix 1839 vulnerabilities.
Researcher reputation: 830
Real name:
lacroute serge
About me:
Computer expert research https://hackerone.com/lacrouteserge/ #celibataire beaufrere #josh previous #crimee now #nenuphar nasa mes publications sont anonymes
aka sergi julien
Contact email:
by email
[email protected]
pgp
https://pastebin.com/raw/KqF20bC1
Alternative Contacts:
lacroute serge
4 bis avenue general de gaulle
64000 pau
france
33695635060
Certifications & Diplomas:
https://map.httpcs.com/author/26492
https://hackerone.com/lacrouteserge
Experience in Application Security
over 5 years
Award / Bug Bounty I prefer:
paypal [email protected]
bitcoin 1MM5j6t8WBaRTwus2tBJEvegU44LU8qYnq
ether 0x1212EE17169244fcCD244Be1c6f0C3cfCfaa1D75
payoneer [email protected]
wired transfer contact m
size XXL
Halls of Fame:
boschs webmini active-campaign ebay xmarks att wiki.scn.sap.com europa.eu simplerisk.com ziprecruteur buzzfeed meetic altervista nokia thumbtack.com pivotal.io dutchdare.nl zooniverse.org
Follow me on:
Twitter
Facebook
LinkedIn
Ethics and Rules:
lacroute serge is required to abide by the ethics and rules of the Open Bug Bounty project. If you reasonably believe that rules are not respected, please report this to us.
Recommendations and Acknowledgements | Full List:
Dear fakessh, thank you for responsible disclosure of a XSS vulnerability on a site. Best regards, Andrei |
Dear fakessh, Thank you for discovering the vulnerability of our website. We were able to immediately fix this vulnerability thanks to your report. We appreciate your kindness. Best regards, SoftBank CSIRT |
On behalf of our company, thank you for the accurate and quick response in disclosing our vulnerability. This was done in a professional and responsible manner through the bug bounty program, giving us time to remediate. |
Thank you fakessh for not only finding and reporting a bug on our college website but then being very helpful in helping me to reproduce the issue and then verifying it as being solved. I am very grateful. |
Thank you for responsible disclosure of a XSS vulnerability on our web site. Thanks also for fast and friendly communication. Matej Zuzcak Head of CSIRT OU University of Ostrava |
Dear fakessh, The University of Vienna would like to thank you for your valuable contribution in finding multiple website security issues. Your input is highly welcome and helps to raise the security level of our educational institution. Servus and greetings from Vienna, Austria. |
Thank you for your vulnerability report! /Hans Liss, Uppsala university |
We would like to thank Fakessh for your carefull and professionally conducted vulnerability report. Wishing you the best Rafael Calzada Security Manager Universidad Carlos III of Madrid [email protected] |
Dear fakessh, Thank you very much for your responsible and professionally conducted vulnerability report. |
Dear Fakessh, The International Service of Geomagnetic Indices would like to thank you for your nice and valuable contribution in finding website security issue. Your message helps us to raise the security level of our international scientific service. Best regards from Strasbourg, France, |
Thank you for responsible disclosure of a XSS vulnerability on a site. Best regards, VDU IT team Lithuania |
Dear, Thanks for participating in responsible disclosure program. The reports you submitted were extremely helpful to our team and provided us the details we needed to resolve the issues that you identified. We are deeply committed to provide a safe and secure experience to our users and are therefore grateful for your efforts to help us improve our services. Best Regards! |
Thank you for responsible disclosure. The report was to the point and actionable. |
Thank you for responsible disclosure of a vulnerability. Very accurate and actionable notification. Regards, Rodrigo Brenes Security Operations Lead |
Thank you for responsible disclosure of XSS vulnerability at one of our sites. Greetings from Varaždin, Croatia |
Dear fakessh, Thank you for your notification about our exposed XSS. Your notification was brief and to the point, providing us with good information so we could confirm and reproduce the report. Best regard Hans-Petter Fjeld Information Security Engineer BASEFARM | Nydalen Allé 37a | 0484 Oslo | Norway Phone: +47 4000 4100 | Mobile: +47 957 28 209 [email protected] | www.basefarm.com technical excellence - caring for your business |
Thank you for your vulnerability report! Computer center @ Scientific Research center of SAZU Ljubljana, Slovenia |
Dear Fakessh, Thank you for your findings. We have enhanced the XSS checking mechanism in the website based on your findings. |
Hello, fakessh! We want to thank you for your vulnerabity report. With your information and collaboration, we could fix a security issue in one of our websites. Great job! |
Dear fakessh, The University of Vienna would like to thank you for your valuable contribution in finding multiple website security issues. Your input is highly welcome and helps to raise the security level of our educational institution. Servus and greetings from Vienna, Austria. |
Thank you for disclosing the XSS on a site under our constituency and all the info provided, so we were able to replicate the problem and initiate the fix. |
Dear Serge, The EPFL would like to thank you for identifying and responsibly disclosing a vulnerability on one of our websites. Your responsiveness was also greatly appreciated. |
Thanks for your report of a vulnerability on our site and quick response to our request of additional information. We were able to fix the problem very soon. |
Dear fakessh, GovCERT Austria would like to thank you for responsibly disclosing web vulnerabilities under gv.at. The operators of the site from today's report also would like to thank you for the notification. Greetings from Vienna, Austria |
Thank you very much for identifying a vulnerability on our website! Our site is a little more secure thanks to you, and that's something my users and I appreciate. |
Thank you for identifying a vulnerability on one of our sites, we were able to solve it really quickly thanks to the information provided by the researcher. |
Thanks for identifying a vulnerability on web site, we were able to improve our coding as a result. |
Dear fakessh, The University of Vienna would like to thank you for your valuable contribution in finding multiple website security issues. Your input is highly welcome and helps to raise the security level of our educational institution. Servus and greetings from Vienna, Austria. |
Thanks for your help in identifying a vulnerability on our site and bringing it to our attention! |
Thanks for reporting the issue with one of our pages. Your quick response helped us quickly identify and fix the vulnerability. |
Very responsive, found XSS that automated tool failed to find. |
Many thanks for a nice and useful example of XSS in our page, fixed very soon! |
Thanks, Fakessh, for reporting the vulnerability on our website. Thanks to your additional information, we were able to quickly fix the problem. |
Dear fakessh, The University of Vienna would like to thank you for your valuable contribution in finding a website security issue. Your input is highly welcome and helps to raise the security level of our educational institution. Servus and greetings from Vienna, Austria. |
Thanks for identifying a vulnerability on one of our sites, we were able to improve our coding practices as a result. |
Yessir! That was a real vulnerability. Thanks for spotting it. And now I can look for more like it. |
The vulnerability you notified our team about also helped identify similar ones across our site. Thank you for bringing this to light and providing a clear proof-of-concept. |
Thank you for notifying us about this vulnerability and for the quick help with details on how to reproduce it. It has been fixed now! |
Thanks for the alert and fast communications. |
Thanks for reporting the XSS vulnerability on our site and the quick response with details of how to reproduce. |
Thanks for your assistance with an issue on our site. |
Thanks for finding and reporting this issue. I had to ask for more specifics about the URL and the researcher responded incredibly quickly. The problem was with somebody elses old php code dating back to the 2000's. They were not sanitizing input at ALL ... YIKES!!! Thanks again! Am looking into having our department provide a small donation. |
Thanks for sharing this issue, all fixed. It was a file not already in use. I solved it by deleting it. Thank you very much. |
Thanks for reporting the XSS vulnerability on our site and the quick response with details of how to reproduce. |
Thanks for sharing this issue and clear demonstration of the exploit. |
Thank you for letting us know about the potential XSS risk on our website. Our IT team is working on making the website more secure now, thanks to you! |
Thankyou for bringing my attention to our bug, i have fixed it now, i hope others find your skills as useful! |
Many thanks for the alert and for the very prompt response. Hopefully now all fixed. |
Thank you for finding this bug I appreciate your work |
Thank you for finding security issue on my website. I appreciate your work! |
Thanks for sharing this issue, all fixed. |
Thanks for bringing this issue to our attention, highly appreciated ! |
Serge, Thank you for helping us finding vulnerabilities in our website. I appreciated your responsiveness and clear demonstration of the exploit. |
Thank you for bringing this to our attention and helping us improve the quality of our site. |
Thanks so much for highlighting a long standing XSS bug on our site. |
Thanks very much for your good work! highly appreciated |
Thanks for bringing this issue to our attention and helping us fix it! Best, Roddy |
Hi fakessh, Thank you for your help. Really appreciate your effort to fix that issue. Thanks and Regards Deepak |
Hi, thanks for pointing that out. It's part of an application, that is beeing phased out. It is fixed now. Regards, Philipp |
Honor Badges
Number of Secured Websites
|
|
|
|
10+ Websites
|
50+ Websites
|
500+ Websites
|
WEB SECURITY VETERAN
1000+ Websites
|
Advanced Security Research
|
|
|
|
WAF Bypasser
|
CSRF Master
30+ Reports
|
AppSec Logic Master
30+ Reports
|
Fastest Fix
Fix in 24 hours
|
Outstanding Achievements
|
|
|
|
Secured OBB
|
OBB Advocate
|
Improved OBB
|
Commitment to Remediate and Patch
|
|
|
|
Patch Master
55% Patched
|
Patch Guru
65% Patched
|
Patch Lord
75% Patched
|
Recommendations and Recognition
|
|
|
|
REPUTABLE
10+ Recommends
|
FAMOUS
25+ Recommends
|
GLOBALLY TRUSTED
50+ Recommends
|
Distinguished Blog Author
|
|
|
|
1 Post
|
3 Posts
|
5+ Posts
|
Research Statistics
Total reports: | 5148 |
Total reports on VIP sites: | 283 |
Total patched vulnerabilities: | 1839 |
Recommendations received: | 60 |
Active since: | 14.02.2017 |
Reported Vulnerabilities
All Submissions VIP SubmissionsFeatured Submissions
Domain | Reported | Status | Type |
---|
27.05.2019 bing openredirect
bing openredirect20.05.2019 Hitachi Incident Response Team (HIRT)
Hitachi HIRT xss reflected
Please login via Twitter to add a recommendation