My First Security Disclosure [HotFattyGirl.Com]

Update 2026-09-23

Ivy reached out following the publication of this article and wanted to clarify one detail: Xsiteability is not a paid hosting service. They operate on a commission basis, taking a percentage of sales rather than charging upfront for hosting. That said, their website does list hosting and bandwidth as included features in a way that implies these would otherwise be separate costs, and their signup process leads straight to an application form with no pricing detail visible upfront so it wasn’t an unreasonable read from the outside. Either way, the correction is noted and appreciated.

On June 5th, 2026, I made my first ever security disclosure and dear readers, somehow my first find ended up being a MySQL exploit and paywall bypass. Not bad for someone who was just checking out a new site launch at 11PM.

Let’s set the stage shall we?

So who had the flaw? That would be Ivy Davenport (aka hotfattygirl), a bisexual USSBBW out of Florida who’s been around since the early 2010s — previously modeled for DimensionsGirls and BBWPinups before striking it big on her own. She’s won multiple industry awards and runs multi-creator projects, so this isn’t some small operation.

On June 5th she relaunched hotfattygirl.com the domain’s been running since 2006 by the way, the copyright notice still reads “All content © 2006 hotfattygirl.com” this time hosted via xsiteability.com. Sweet lord did things go downhill fast.

Within two hours of launch I’d already found two major issues.

ISSUE 1 — PAYMENT BYPASS VIA DIRECT VIDEO URL
Any video on the site could be accessed directly via its URL without hitting the payment gateway. Meaning anyone with or who could guess the direct stream link got in free.

ISSUE 2 — PHP ERRORS EXPOSED PUBLICLY
The site was displaying live PHP warnings to anyone who visited, including full server file paths like /home/xsiteabi/public_html/x/users/_userfolderincludes/stream.php. Handing that information to anyone who looked.

Now here’s where it gets interesting dear readers  the fun part isn’t just the paywall bypass. The site’s PHP code used a server variable called REDIRECT_REMOTE_USER to verify authentication before serving content. That variable wasn’t being set, meaning the authentication check was failing silently and just… letting people through anyway. When that broken state hit the database layer, MySQL was receiving null values instead of user data which is exactly what those public PHP errors were showing. The same broken auth flow likely ran across the whole codebase. Account pages, payment pages, all of it.

I didn’t go looking for payment data I’m actually a decent person but the shape of the vulnerability meant it was probably there to find if someone less scrupulous came along.

Oh and here’s the fun part. XSiteAbility.com run by ASAP Incorporated out of Tampa Bay, Florida by the way sells this as a platform. As in Ivy paid someone else to handle all the technical side for her. The vulnerable code wasn’t even hers. She trusted a platform that shipped broken authentication on launch day.

So I did the right thing and reported it. June 5th I contacted Ivy’s site email, her X account, and XSiteAbility.com directly. All three went into the void. For three months dear readers. Three months of nothing while a 15 year fanbase was being migrated into a platform with a busted authentication layer.

Ivy had been in hospital with a leg injury during part of this, which I genuinely understand I wished her well publicly and still got ignored on the security issue. XSiteAbility though? No excuse. They were directly notified as the platform provider on day one and said nothing.

What finally worked? Finding the Gmail address she’d listed for commission work. Sent the email at 7:19PM on September 17th. Got a response at 7:33PM fourteen minutes later. Fixed within days after that.

To her credit once it reached her properly she was responsive and grateful. The system around her just completely failed.

I’ve yet to see any proof the vulnerability was exploited  and since I found it within two hours of launch the window was hopefully limited  but whether other creators on the xsiteability platform were running the same broken code remains an open question nobody has publicly answered.

The closing lessons dear readers:

If you’re a developer: test your authentication before launch. Seriously.

If you’re a creator buying a platform: ask what their security disclosure process is before you sign up. Ivy didn’t write this code. She just trusted someone who did.

And if someone reaches out about a security flaw, check all your inboxes. Mine sat unread for three months not because nobody cared but because they never landed where they needed to

Comments (0)

No comments yet.

Leave a Reply

Your email address will not be published. Required fields are marked *