Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Broken Link on who-covid-19-mobile-app's Vulnerability Submission Form on Hackerone #2019

Open
jaimaakali opened this issue Aug 13, 2021 · 2 comments
Labels
needs:triage New issue that needs triage resolved:stale No recent activity on the issue or PR source:public Issues created by the public

Comments

@jaimaakali
Copy link

Steps To Reproduce:

Visit https://hackerone.com/who-covid-19-mobile-app/reports/new?type=team&report_type=vulnerability

Click on Security Page.

After that, you'll be redirected to the 404 HackerOne page.

This will impersonate your security page and steal legitimate reports.

References:
https://edoverflow.com/2017/broken-link-hijacking

Similar report : https://hackerone.com/reports/1225299

POC video : recording-1624273892143.webm

@171217

Impact

New researchers can be further deceived if they click on the hijacked link.

A specific case might be for a malicious user to create a fake account on that broken redirection link and deceive researchers arriving on that link. For example, the attacker can ask the researcher to submit his report to him first and if he approves, then only he can submit it to your official page. In this way, it can cause huge damage to your company if a critical severity report is mis-directed to the attacker.

@jaimaakali jaimaakali added needs:triage New issue that needs triage source:public Issues created by the public labels Aug 13, 2021
@jaimaakali
Copy link
Author

Original report : https://hackerone.com/reports/1239670

Reporter : @171217

@stale
Copy link

stale bot commented Sep 14, 2021

This item has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale bot added the resolved:stale No recent activity on the issue or PR label Sep 14, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs:triage New issue that needs triage resolved:stale No recent activity on the issue or PR source:public Issues created by the public
Projects
None yet
Development

No branches or pull requests

1 participant