Hi and supporters,
You should not use this app. In 5 minutes, I managed to get:
- the list of all the people registered
- name
- Photo
- personal messages
- token to steal their session
Thread ⬇️
Conversation
Currently there are 1607 users in the application and 128 rooms
3
1
70
A room is a discussion between two people when they matched
2
1
63
The longest conversation is a discussion between the devs of the app 😂
3
8
171
"Are you friends with the people who made this app?"
1
1
58
Quote Tweet
It's probably not a good idea to expose all your ids and keys... In the app you can find:
- google_api_key
- google_app_id
- google_crash_reporting_api_key
- default_web_client_id
- facebook_app_id
- RNB_GOOGLE_PLAY_LICENSE_KEY
1
8
73
I'm sad, I expected a lot of bot replies 😂
7
1
101
Quote Tweet
I made a small proof of concept to show how the database of the Donald Daters app is vulnerable. With this POC I can:
- see all private messages
- see all user info
- delete what I want: a message, an user, the all database, ...
Show this thread
0:28
12.5K views
3
8
56
1
2
41

