# Looking for security contact at Neopets

**URL:** <https://community.disclose.io/t/looking-for-security-contact-at-neopets/154>\
**Category:** Hacker Connect\
**Created:** [December 28, 2020, 5:09am UTC](https://community.disclose.io/t/looking-for-security-contact-at-neopets/154 "2020-12-28T05:09:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![johnjhacking](https://yyz2.discourse-cdn.com/flex028/user_avatar/community.disclose.io/johnjhacking/32/211_2.png) [@johnjhacking](https://community.disclose.io/u/johnjhacking)\
**Post date:** [December 28, 2020, 5:09am UTC](https://community.disclose.io/t/looking-for-security-contact-at-neopets/154/1 "2020-12-28T05:09:23Z")

</div>

Hello all,

I’ve been dealing with an issue with Neopets, the online flash game. With the Help of [@tensor\_bodega](https://twitter.com/tensor_bodega) I was able to completely dump the entire Codebase and see Employee Emails, LDAP Credentials, Database Credentials, Internal IPs, User IPs, etc. This is a serious problem - and being that I had experience with Neopets support in the past, I decided to contact them via public means on Twitter: [https://twitter.com/johnjhacking/status/1342921353310027776?s=20](https://twitter.com/johnjhacking/status/1342921353310027776?s=20)

They had me reach out via DM and told me submit a support ticket. I submitted multiple vulnerabilities, but as of now they have only resolved the less severe ones and not the vulnerabilities resulting in a full dump of their Codebase w/server configs and information.

If anyone has a contact beyond the Neopets support line, please let me know. I don’t like playing Support → Developer coordination games. This is urgent and critical because PII is exposed and some of these individuals are Children.

---

<div class="post-metadata">

**Author:** ![johnjhacking](https://yyz2.discourse-cdn.com/flex028/user_avatar/community.disclose.io/johnjhacking/32/211_2.png) [@johnjhacking](https://community.disclose.io/u/johnjhacking)\
**Post date:** [December 28, 2020, 7:05pm UTC](https://community.disclose.io/t/looking-for-security-contact-at-neopets/154/2 "2020-12-28T19:05:23Z")

</div>

Timeline for tracking:

**2020-12-26:** Found vulnerabilities  
**2020-12-26:** Reached out to Neopets on Twitter, support triaged my issue  
**2020-12-27:** Emailed Neopets Support for a follow-up, no answer  
**2020-12-28:** Emailed Neopets Support for a follow-up, no answer  
**2020-12-28:** Validated the fix of 5 medium vulnerabilities, most critical vulns still pending fix.  
**2020-12-28:** Critical Vulnerabilities fixed, several medium-low impact vulnerabilities remain.  
**2020-12-28:** Recheck revealed more vulnerabilities, looping back for more reporting.

---

<div class="post-metadata">

**Author:** ![disclose](https://yyz2.discourse-cdn.com/flex028/user_avatar/community.disclose.io/disclose/32/9_2.png) [@disclose](https://community.disclose.io/u/disclose)\
**Post date:** [December 30, 2020, 1:46am UTC](https://community.disclose.io/t/looking-for-security-contact-at-neopets/154/3 "2020-12-30T01:46:45Z")

</div>

Hey @johnjhacking - Was there progress on this?

---

<div class="post-metadata">

**Author:** ![johnjhacking](https://yyz2.discourse-cdn.com/flex028/user_avatar/community.disclose.io/johnjhacking/32/211_2.png) [@johnjhacking](https://community.disclose.io/u/johnjhacking)\
**Post date:** [January 2, 2021, 8:17pm UTC](https://community.disclose.io/t/looking-for-security-contact-at-neopets/154/4 "2021-01-02T20:17:45Z")

</div>

Yes sorry, circling back now.

All 15 vulnerabilities that have been reported, including the two most critical resulting in the dump of credentials and proprietary code, are fixed. I have commended Neopets publicly, and if Disclose wants to, maybe we can give them a public shout as well.

---

<div class="post-metadata">

**Author:** ![sickcodes](https://yyz2.discourse-cdn.com/flex028/user_avatar/community.disclose.io/sickcodes/32/29_2.png) [@sickcodes](https://community.disclose.io/u/sickcodes)\
**Post date:** [February 8, 2021, 11:30am UTC](https://community.disclose.io/t/looking-for-security-contact-at-neopets/154/5 "2021-02-08T11:30:10Z")

</div>

Just posting an update here for readers:

John disclosed this vulnerability:

> **[Amphion Forum: Spotlight on Security and Internet of Things](https://securityledger.com/2013/12/amphion-forum-spotlight-on-security-and-internet-of-things/)**
>
> The risks posed by a mushrooming population of Internet-connected devices will be the focus of The Amphion Forum in San Francisco this week.

> **[Reddit - The heart of the internet](https://www.reddit.com/r/neopets/comments/kkphhy/neopets_got_breached/)**

[![](https://canada1.discourse-cdn.com/flex028/uploads/disclose1/original/1X/a4558236c2eee79059dc287f5f6ee45c5532454c.jpeg "Neopets Hack Update: The Neopets Team's PR Response") ](https://www.youtube.com/watch?v=2TlvEkFhLps)

---

<div class="post-metadata">

**Author:** ![johnjhacking](https://yyz2.discourse-cdn.com/flex028/user_avatar/community.disclose.io/johnjhacking/32/211_2.png) [@johnjhacking](https://community.disclose.io/u/johnjhacking)\
**Post date:** [February 15, 2021, 8:41pm UTC](https://community.disclose.io/t/looking-for-security-contact-at-neopets/154/6 "2021-02-15T20:41:43Z")

</div>

It was a good experience, and met with an adequate and professional response.
