Log inSign up
Ian Carroll
1,860 posts
Image
user avatar
Ian Carroll
@iangcarroll
Founder at @SeatsAero. Travel/points, application security, security research, etc. bsky.app/profile/ian.sh
Las Vegas, NV
ian.sh
Joined July 2014
1,154
Following
24.3K
Followers
  • Pinned
    user avatar
    Ian Carroll
    @iangcarroll
    Aug 11, 2024
    First DEF CON talk with @LennertWo was a success!
    Image
    Image
    Image
    112K
  • user avatar
    Ian Carroll
    @iangcarroll
    Dec 1, 2022
    Well, ChatGPT knows AWS IAM policies... holy shit.
    Image
    Image
  • user avatar
    Ian Carroll
    @iangcarroll
    Apr 29, 2022
    we got a shell on the topgolf kiosk
    Image
  • user avatar
    Ian Carroll
    @iangcarroll
    Aug 29, 2024
    In April, @samwcyo and I discovered a way to bypass airport security via SQL injection in a database of crewmembers. Unfortunately, DHS ghosted us after we disclosed the issue, and the TSA attempted to cover up what we found. Here is our writeup:
    Bypassing airport security via SQL injection
    Bypassing airport security via SQL injection
    From ian.sh
    189K
  • user avatar
    Ian Carroll
    @iangcarroll
    Jun 13, 2020
    chrome://dino 0day, brought to you by security happy hour (bug bounty pls) checkForCollision = () => false; Runner.instance_.setSpeed(50);
    Image
    00:00
  • user avatar
    Ian Carroll
    @iangcarroll
    Mar 14, 2021
    1Gbps of sustained outbound transfer on aws is about $21,000/month in us-east-1. that's it. that's the tweet.
  • user avatar
    Ian Carroll
    @iangcarroll
    Nov 19, 2020
    ARM-based macOS can run iOS apps + network traffic/cert store is tied to macOS = perfect for iOS app hacking
    Image
  • user avatar
    Ian Carroll
    @iangcarroll
    Dec 10, 2023
    About 1.5 years ago, I started Seats.aero as a fun side project to help me book better award flights with my points. To my surprise, it grew much faster than I ever expected, and ended up becoming my full-time job. As the year ends, we just hit $1.5M in ARR and now
    Image
    Image
    423K
  • user avatar
    Ian Carroll
    @iangcarroll
    Nov 4, 2021
    Yay, I was awarded a $75,000 bounty on @Hacker0x01! hackerone.com/ian #TogetherWeHitHarder Five $15,000 reports to one program using an issue that CookieMonster would catch! Not as straightforward though; CVE soon :)
    Image
    hackerone.com
    HackerOne profile - ian
    hacking things - https://ian.sh
  • user avatar
    Ian Carroll
    @iangcarroll
    Sep 6, 2022
    I got promoted today to Staff Security Engineer at Robinhood!
  • user avatar
    Ian Carroll
    @iangcarroll
    Mar 30, 2025
    Pretty crazy to look back on this as we just hit $8M ARR + 500k MAU! @SeatsAero is still fully bootstrapped, but I think we are going to have to hire soon. Have hit the limit on being "solo" where you start hampering your own progress. Even just support is quite difficult now
    user avatar
    Ian Carroll
    @iangcarroll
    Dec 10, 2023
    About 1.5 years ago, I started Seats.aero as a fun side project to help me book better award flights with my points. To my surprise, it grew much faster than I ever expected, and ended up becoming my full-time job. As the year ends, we just hit $1.5M in ARR and now
    Image
    Image
    164K
  • user avatar
    Ian Carroll
    @iangcarroll
    Apr 16, 2020
    CVE-2020-7066 is a pretty neat SSRF vector in PHP; URL parsing differences strike yet again.
    Image
  • user avatar
    Ian Carroll
    @iangcarroll
    Jun 14, 2021
    I wrote about how I exploited a bunch of outdated Apache Airflow instances in bug bounty programs and earned over $13,000 for it!
    ian.sh
    Exploiting outdated Apache Airflow instances in bug bounties
    Apache Airflow is a popular system for executing workflows, such as copying and transforming data between data sources. I first ran into an Airflow instance exposed to the internet on a bug bounty...
  • user avatar
    Ian Carroll
    @iangcarroll
    Nov 2, 2021
    Excited to share a small thing I've been working on: fast tooling for detecting misconfigured session implementations in web apps. CookieMonster rapidly finds misconfigured secret keys in applications using Laravel, Flask, JWTs, and more!
    Introducing CookieMonster: a tool for breaking stateless authentication
    Introducing CookieMonster: a tool for breaking stateless authentication
    From ian.sh

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement