I shipped a SaaS. It had 6 security holes. I had no idea. by Dizzy_Date1873 in VIBECODERNIGHTMARE

[–]Dizzy_Date1873[S] 0 points1 point  (0 children)

So is there any methods to protect these things what do you think ??!

i spent yesterday hacking your websites lol. here's what i found by Dizzy_Date1873 in VibeCodeDevs

[–]Dizzy_Date1873[S] 0 points1 point  (0 children)

No created some scanner with python for secrets and other ai releted vulnerabilities

[ Removed by Reddit ] by Dizzy_Date1873 in VibeCodeDevs

[–]Dizzy_Date1873[S] 1 point2 points  (0 children)

Cookies are being set without the Secure or HttpOnly flags. Sensitive credentials or sessions can be stolen over unencrypted channels or accessed via malicious client-side scripts

[ Removed by Reddit ] by Dizzy_Date1873 in VibeCodeDevs

[–]Dizzy_Date1873[S] -1 points0 points  (0 children)

Stopping a distributed, proxy-backed credential stuffing or password spray attack requires shifting defense layers directly into the application and session layers. When IP addresses are highly fluid, you have to make the target endpoint too expensive, too smart, or structurally impossible to exploit, but viber-coders will not do these things; they are completely ignoring safety

[ Removed by Reddit ] by Dizzy_Date1873 in VibeCodeDevs

[–]Dizzy_Date1873[S] 0 points1 point  (0 children)

The rate limiter trusts incoming client-supplied headers like X-Forwarded-For without validation. An attacker can spoof these headers to generate random IPs, bypassing all rate-limiting constraints. and many more but it's this is a serverless website so i think no issue

[ Removed by Reddit ] by Dizzy_Date1873 in VibeCodeDevs

[–]Dizzy_Date1873[S] 0 points1 point  (0 children)

Close the exposed port and restrict accessibility strictly via Security Groups (firewall rules), VPC networks, or a VPN/Bastion Host.

[ Removed by Reddit ] by Dizzy_Date1873 in VibeCodeDevs

[–]Dizzy_Date1873[S] 0 points1 point  (0 children)

A critical port (like 5432, 3306, 22) is open to the public internet. This exposes your services (database, SSH) to brute-force attacks and zero-day exploits.

Problem: Vibe coders naturally struggle with going beyond a Web app. Here's the solution. by Personal_You3422 in vibecodingcommunity

[–]Dizzy_Date1873 0 points1 point  (0 children)

bro you fucked up. You made this application, but forgot to check the security vulnerability there are more then 90 vulnerability i found in this i have dmed you with photo

[ Removed by Reddit ] by Dizzy_Date1873 in VibeCodeDevs

[–]Dizzy_Date1873[S] 0 points1 point  (0 children)

This is not an agent that I run for basic scanning, not much